KishanBagaria / padding-oracle-attacker
🔓 CLI tool and library to execute padding oracle attacks easily, with support for concurrent network requests and an elegant UI.
☆201Updated last year
Related projects ⓘ
Alternatives and complementary repositories for padding-oracle-attacker
- A list of files / paths to probe when arbitrary files can be read on a Microsoft Windows operating system☆199Updated last year
- Piper Burp Suite Extender plugin☆115Updated 8 months ago
- A natural evolution of Burp Suite's Repeater tool☆194Updated 9 months ago
- DNS rebinding toolkit☆250Updated last year
- Everything you need about Burp Extension Generation☆152Updated last year
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆209Updated 3 years ago
- Linux privilege escalation via LXD☆132Updated 4 years ago
- 🏴☠️ Bypass Same Origin Policy with DNS-rebinding to retrieve local server files 🏴☠️☆196Updated 5 years ago
- DupeKeyInjector☆134Updated 2 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆253Updated 3 years ago
- notes and code on past CTFs☆100Updated 3 years ago
- Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.☆171Updated 3 years ago
- ☆128Updated 3 years ago
- Automatic tool for DNS rebinding-based SSRF attacks☆293Updated 4 years ago
- ☆144Updated 2 years ago
- CLI tool for PKCS7 padding oracle attacks☆134Updated 3 years ago
- Words list generator to crack security tokens☆110Updated 4 years ago
- DNS Rebinding Exploitation Framework☆482Updated 3 years ago
- ☆259Updated 5 years ago
- d(ockerp)wn - a docker pwn tool manager☆155Updated 3 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆585Updated 3 years ago
- Predict Mongo ObjectIds☆125Updated 6 years ago
- [A]ndroid [A]pplication [P]entest [G]uide☆122Updated 5 years ago
- Alphanumeric Shellcode (x86) Encoder☆73Updated 2 years ago
- Bypassing FILTER_SANITIZE_EMAIL & FILTER_VALIDATE_EMAIL filters in filter_var for SQL Injection ( xD )☆31Updated 5 years ago
- Burp Suite Extension to monitor new scope☆195Updated 3 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆344Updated 2 years ago
- Poodle (Padding Oracle On Downgraded Legacy Encryption) attack CVE-2014-3566☆251Updated last year
- A collection of scripts, and tips and tricks for hacking k8s clusters and containers.☆134Updated last month
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆252Updated 2 years ago