aapooksman / writeups
☆12Updated last year
Alternatives and similar repositories for writeups:
Users that are interested in writeups are comparing it to the libraries listed below
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last month
- Create tar/zip archives that try to exploit zipslip vulnerability.☆47Updated 6 months ago
- A Simple CVE-2022-39299 PoC exploit generator to bypass authentication in SAML SSO Integrations using vulnerable versions of passport-sam…☆19Updated 2 years ago
- A collection of utilities for building extensions using Burp's Montoya API☆50Updated 9 months ago
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆27Updated 6 years ago
- ☆31Updated 2 years ago
- ☆28Updated this week
- an Evil Java RMI Registry.☆49Updated 2 years ago
- Piper Burp Suite Extender plugin☆14Updated this week
- recon.cloud is website that scans AWS, Azure and GCP public cloud footprint this GO tool only utilize its API for getting result to termi…☆24Updated 2 years ago
- Dependency Confusion Security Testing Tool☆47Updated 2 years ago
- Jumpstart multiple WebSocket servers quickly☆31Updated 3 years ago
- This script just implement a proxy over h2cSmuggler so you can navigate in your browser making requests to the back-end server.☆37Updated 2 years ago
- Make better use of the embedded browser that comes by default with Burp☆43Updated last year
- Ansible build for Afl++ Frida-Mode☆23Updated 10 months ago
- A tool for check available dependency packages across npmjs, PyPI or RubyGems registry.☆28Updated 3 years ago
- Simple PoC for demonstrating Race Conditions on Websockets☆56Updated last year
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Updated 3 years ago
- FireProx written in Go☆19Updated 11 months ago
- The authentication bypass vulnerability in GitHub Enterprise Server (GHES) allows an unauthorized attacker to access an instance of GHES …☆50Updated 10 months ago
- Burp extension to generate multi-step CSRF POC.☆29Updated 5 years ago
- Tool to spray AWS Console IAM Logins☆29Updated 2 years ago
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆20Updated 7 months ago
- ☆11Updated 2 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 6 months ago
- Java archive implant toolkit.☆60Updated this week
- ☆23Updated 2 months ago
- ☆56Updated 3 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated last month
- Simple WebSocket fuzzer☆32Updated last year