WConsole Extractor is a python library which automatically exploits a Werkzeug development server in debug mode. You just have to write a python function that leaks a file content and you have your shell :)
☆66Jun 27, 2025Updated last year
Alternatives and similar repositories for wconsole_extractor
Users that are interested in wconsole_extractor are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This tool allows to automatically test for Content Security Policy bypass payloads.☆45Sep 4, 2024Updated last year
- dead-simple blog template powered by Markdown and PHP☆10May 6, 2025Updated last year
- ☆13Jun 27, 2023Updated 3 years ago
- CVE-2024-34102: Unauthenticated Magento XXE☆14Jan 12, 2025Updated last year
- Auto-Recon script that will help you in the Burp Suite Certified Practitioner Examor with any web-security lab.☆59Jul 8, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆149Dec 9, 2024Updated last year
- Generates a DEBUG PIN for flask applications based on Werkzeug☆20Nov 22, 2023Updated 2 years ago
- Full write-up for the Active Directory Lab built for Barbhack 2025 by @mpgn and my contributions.☆24Sep 2, 2025Updated 10 months ago
- ☆11Jan 8, 2023Updated 3 years ago
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆150Feb 4, 2026Updated 5 months ago
- A python script to automatically list vulnerable Windows ACEs/ACLs.☆67Updated this week
- This website is used to automatically scan files during CTF.☆13May 31, 2023Updated 3 years ago
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆809Dec 9, 2025Updated 7 months ago
- Real-Time JavaScript reverse engineering and debugging suite - Burp Suite, but for JavaScript☆18Jul 23, 2025Updated 11 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆135Dec 6, 2023Updated 2 years ago
- Drupalwned is a script designed to escalate a Cross-Site Scripting (XSS) vulnerability to Remote Code Execution (RCE) or other's critical…☆41Dec 24, 2023Updated 2 years ago
- medor is an OSINT tool that enables you to discover a WordPress website IP behind a WAF or behind Onion Services.☆19Jul 6, 2024Updated 2 years ago
- A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.☆145Dec 23, 2025Updated 6 months ago
- angr-wrapper is a simple script to automatise and accelerate your basic use of angr (to solve CTF challenges for example)☆14Dec 18, 2021Updated 4 years ago
- Automatically extract and decrypt all configured scanning credentials of a Lansweeper instance.☆47Nov 29, 2024Updated last year
- A collection of Server-Side Prototype Pollution gadgets and exploits☆236Feb 6, 2025Updated last year
- A collection of challenges I made for CTF competitions☆16Jan 28, 2026Updated 5 months ago
- Attacking indiscriminately every header, cookie, GET and POST parameter with blind fury.☆13Sep 25, 2025Updated 9 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- SSH & FTP brute-forcing tool written in python☆11Oct 2, 2024Updated last year
- A simple pickle assembler to make handcrafting pickle bytecode easier.☆15Apr 16, 2021Updated 5 years ago
- Generate email permutations from a name and verify if this email exist with different providers (gmail, duckduckgo, yahoo, yandex)☆42Feb 25, 2025Updated last year
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆244Oct 8, 2024Updated last year
- A PoC exploit for CVE-2024-4577 - PHP CGI Argument Injection Remote Code Execution (RCE)☆10Jul 12, 2024Updated 2 years ago
- ☆35Jan 31, 2026Updated 5 months ago
- A python module to explore the object tree to extract paths to interesting objects in memory.☆105Jan 31, 2025Updated last year
- Check robustness of your (their) Active Directory accounts passwords☆45Mar 13, 2026Updated 4 months ago
- A python script to dump all the challenges locally of a CTFd-based Capture the Flag.☆173Apr 3, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆114Jun 23, 2025Updated last year
- A web based OSINT ressource and tool☆239May 25, 2026Updated last month
- CVE-2022-30780 - lighttpd remote denial of service☆17Mar 16, 2024Updated 2 years ago
- apkfram was written in order to help any mobile penetration testers to identify the Framework used to develop the Android application.☆12Oct 9, 2024Updated last year
- A web-based editor for FoxDot☆15May 8, 2025Updated last year
- CVE-2024-28955 Exploitation PoC☆34Jul 1, 2024Updated 2 years ago
- A straightforward tool for exploiting SMTP Smuggling vulnerabilities.☆14Jul 22, 2024Updated last year