KishanBagaria / padding-oracle-attacker
🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.
☆206Updated 2 years ago
Alternatives and similar repositories for padding-oracle-attacker:
Users that are interested in padding-oracle-attacker are comparing it to the libraries listed below
- notes and code on past CTFs☆103Updated 3 years ago
- 🏴☠️ Bypass Same Origin Policy with DNS-rebinding to retrieve local server files 🏴☠️☆199Updated 6 years ago
- CLI tool for PKCS7 padding oracle attacks☆137Updated 4 years ago
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆210Updated 4 years ago
- Linux post exploitation privilege escalation enumeration☆256Updated 4 years ago
- ☆91Updated 6 years ago
- SOCKS5 and HTTP over TURN/STUN proxy☆178Updated last year
- A natural evolution of Burp Suite's Repeater tool☆197Updated last year
- Predict Mongo ObjectIds☆132Updated 7 years ago
- Script to recover mt_rand()'s seed with only two outputs and without any bruteforce.☆152Updated 5 years ago
- A toolbox for extracting RSA private keys from public keys.☆183Updated 3 years ago
- Multi-threaded Padding Oracle attacks against any service. Written in Rust.☆97Updated 2 years ago
- DupeKeyInjector☆135Updated 3 years ago
- DNS rebinding toolkit☆253Updated last year
- RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities☆433Updated 2 years ago
- XS-Leak Browser Test Suite☆80Updated last year
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆596Updated 4 years ago
- A Python implementation that facilitates finding timeless timing attack vulnerabilities.☆123Updated this week
- Automatic exploit generation for simple linux pwn challenges.☆321Updated last year
- AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.☆42Updated last year
- Modular command-line tool to parse, create and manipulate JWT tokens for hackers☆104Updated 2 years ago
- A mini webserver with FTP support for XXE payloads☆330Updated last year
- Everything you need about Burp Extension Generation☆153Updated 2 years ago
- ☆264Updated 6 years ago
- A portable, padding oracle exploit API☆326Updated 2 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆349Updated 2 years ago
- Burp Bounty is a extension of Burp Suite that improve an active and passive scanner by yourself. This extension requires Burp Suite Pro.☆71Updated 3 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆259Updated 3 years ago
- ☆129Updated 4 years ago
- DNS Rebinding Exploitation Framework☆488Updated 4 years ago