PortSwigger / flow
Extension providing view with filtering capabilities for both complete and incomplete requests from all burp tools.
☆24Updated 3 years ago
Alternatives and similar repositories for flow
Users that are interested in flow are comparing it to the libraries listed below
Sorting:
- Confluence Widget Connector path traversal (CVE-2019-3396)☆22Updated 5 years ago
- Study about HQL injection exploitation.☆51Updated 9 years ago
- ☆42Updated 5 years ago
- A simple scanner to find and brute force tomcat manager logins☆28Updated 5 years ago
- miscellaneous security research stuff☆37Updated 5 years ago
- Repo for proof of concept exploits and tools.☆56Updated 4 years ago
- YSOSERIAL Integration with burp suite☆40Updated 3 years ago
- Burp Extension to manipulate AES encrypted payloads☆14Updated 3 years ago
- Full TTY reverse shell over SSH☆58Updated 4 years ago
- ZAP/Burp plugin that generate script to reproduce a specific HTTP request (Intended for fuzzing or scripted attacks)☆29Updated 3 years ago
- All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities☆27Updated 3 years ago
- Burp Suite plugin created for using Collaborator tool during manual testing☆19Updated 3 years ago
- Burp Suite Attack Selector Plugin☆60Updated 7 years ago
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆25Updated 5 years ago
- XSS payloads for edge cases☆34Updated 6 years ago
- ☆25Updated 7 years ago
- Pulse Secure SSL VPN pre-auth file reading☆50Updated 5 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Updated 6 years ago
- ZIP File Raider - Burp Extension for ZIP File Payload Testing☆71Updated 4 years ago
- OWASP Skanda - SSRF Exploitation Framework☆38Updated 11 years ago
- This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, …☆53Updated 2 years ago
- A server vulnerable to XXE that can be used to test payloads using the xxer tool.☆26Updated 7 years ago
- CVE-2017-10271 WEBLOGIC RCE (TESTED)☆38Updated 7 years ago
- CVE-2019-9580 - StackStorm: exploiting CORS misconfiguration (null origin) to gain RCE☆32Updated 6 years ago
- Proof of concept written in Python to show that in some situations a SSRF vulnerability can be used to steal NTLMv1/v2 hashes.☆57Updated 7 years ago
- Environment for CVE-2019-6340 (Drupal)☆43Updated last year
- Extension providing view with filtering capabilities for both complete and incomplete requests from all burp tools.☆48Updated 4 years ago
- A Burp Suite extension that automatically marks similar requests as 'out-of-scope'.☆43Updated 5 years ago
- PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM☆52Updated 7 years ago
- CVE-2020-12828 PoC and Analysis.☆29Updated 4 years ago