PortSwigger / serialization-examplesLinks
☆42Updated last year
Alternatives and similar repositories for serialization-examples
Users that are interested in serialization-examples are comparing it to the libraries listed below
Sorting:
- LFI to RCE via phpinfo() assistance or via controlled log file☆69Updated 2 years ago
- A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection☆70Updated 4 years ago
- NotSoCereal: A Deserialization exploit playground☆53Updated 3 years ago
- Wordlist to bruteforce for LFI☆124Updated 5 years ago
- ☆37Updated 2 years ago
- Preparation for OSWE☆42Updated 5 years ago
- Workshop given at Hack in Paris 2019☆122Updated 2 years ago
- A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration☆79Updated 4 years ago
- Small tool to automate SSRF wordpress and XMLRPC finder☆81Updated 2 years ago
- Python exploit for the CVE-2021-22204 vulnerability in Exiftool☆94Updated 4 years ago
- ☆34Updated 3 years ago
- Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473☆108Updated last year
- An MS Sharepoint and Frontpage Auditing Tool☆50Updated 7 months ago
- ☆157Updated 3 years ago
- LFI Payloads List coolected from github repos☆80Updated 5 years ago
- Exploit and Check Script for CVE 2022-1388☆58Updated 2 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆72Updated 3 years ago
- Vulnerable SAML infrastructure training applicaiton☆53Updated 2 years ago
- Prototype Pollution Scanner☆121Updated 4 years ago
- Burp Extension that copies a request and builds a FFUF skeleton☆111Updated last year
- Phar + JPG Polyglot generator and playground (CTF CODE)☆90Updated 6 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆31Updated last year
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆77Updated last year
- BurpSuite using the document and some extensions☆69Updated 5 years ago
- HTTP verb tampering & methods enumeration☆61Updated 3 years ago
- A list of threat sinks used in the manual security source code review for application security☆72Updated 2 years ago
- ☆26Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- A simple remote scanner for Atlassian Jira☆121Updated 2 years ago