PortSwigger / java-deserialization-scannerLinks
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
☆28Updated 3 years ago
Alternatives and similar repositories for java-deserialization-scanner
Users that are interested in java-deserialization-scanner are comparing it to the libraries listed below
Sorting:
- YSOSERIAL Integration with burp suite☆41Updated 3 years ago
- Burp Suite extension to passively scan for applications revealing server error messages☆65Updated last year
- ☆43Updated 5 years ago
- A Burp extension to show the Collaborator client in a tab☆36Updated 2 years ago
- The Web Audit Search Engine - Index and Search HTTP Requests and Responses in Web Application Audits with ElasticSearch☆23Updated 6 years ago
- siberas JMX exploitation toolkit☆131Updated 2 years ago
- A server vulnerable to XXE that can be used to test payloads using the xxer tool.☆26Updated 7 years ago
- HTML5 WebSocket message fuzzer☆147Updated 6 years ago
- Custom Parameter Handler extension for Burp Suite.☆44Updated 4 years ago
- ☆108Updated 3 years ago
- Burp Suite extension for JAX-RS☆65Updated 8 years ago
- Burp extension to passively scan for applications revealing software version numbers☆32Updated last year
- ☆51Updated 5 years ago
- Java serialization brute force attack tool.☆123Updated 8 years ago
- Practice hacking JWT tokens☆116Updated 3 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆53Updated 12 years ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆100Updated 6 years ago
- Proof of concept for CVE-2020-5902☆72Updated 5 years ago
- Plattform to develop and experiment with existing java web attacks.☆31Updated 7 years ago
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆54Updated 3 years ago
- Hacking Artifactory with server side template injection☆51Updated 5 years ago
- ☆104Updated 5 years ago
- Fuzzing for LFI using Burpsuite☆65Updated 9 years ago
- Atlassian JIRA Template injection vulnerability RCE☆93Updated 6 years ago
- A simple Burp extension for scanning stuffs in CTF☆31Updated 7 years ago
- This tool was written as PoC to article https://waf.ninja/libinjection-fuzz-to-bypass/☆37Updated 8 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆124Updated 7 years ago
- A Burp extension for generic extraction and reuse of data within HTTP requests and responses.☆94Updated last week
- Burp extension☆58Updated 7 years ago
- This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, …☆53Updated 2 years ago