alex91ar / randomstringutils
Cracker for Apache.lang.commons RandomStringUtils(). Code for "The Java Soothsayer" talk at EkoParty 2017 by Alejo Popovici.
☆32Updated 7 years ago
Alternatives and similar repositories for randomstringutils:
Users that are interested in randomstringutils are comparing it to the libraries listed below
- A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.☆26Updated 10 years ago
- Simple trick to increase readability of exceptions raised by Burp extensions written in Python☆42Updated 8 years ago
- Study about HQL injection exploitation.☆51Updated 8 years ago
- ☆38Updated 4 years ago
- A Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.☆41Updated 2 years ago
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆12Updated last year
- Remote Java classpath enumeration via deserialization☆22Updated last year
- Argument Injection in Dragonfly Ruby Gem☆16Updated 3 years ago
- A malicious LDAP server for JNDI injection attacks☆73Updated 5 months ago
- UUID issues for Burp Suite☆51Updated 2 years ago
- .NET Deserialization Passive Scanner☆45Updated 7 years ago
- ☆17Updated 2 years ago
- #INFILTRATE19 raptor's party pack.☆30Updated last year
- ☆33Updated 3 years ago
- This is a Burp extension for adding additional payloads to active scanner that require out-of-band validation. Works great with XSSHunter☆20Updated 8 years ago
- A framework for exploiting padding oracles in network-based applications☆26Updated 2 years ago
- This repository contains hit lists to use for web application content discovery.☆11Updated 7 years ago
- Parse X509 certificates to get the (sub)domains in it.☆28Updated 6 years ago
- My fuzzing workshop from PHDays9☆26Updated 5 years ago
- Full TTY reverse shell over SSH☆58Updated 4 years ago
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆24Updated 5 years ago
- DEF CON 26 WorkShop - Fuzzing FTW☆19Updated 6 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆52Updated 11 years ago
- Burp Extension for AWS Signing☆88Updated 3 months ago
- Kerberom is a tool aimed to retrieve ARC4-HMAC'ed encrypted Tickets Granting Service (TGS) of accounts having a Service Principal Name (S…☆36Updated 6 years ago
- A BurpSuite extension for beautifying .NET message parameters and hiding some of the extra clutter that comes with .NET web apps (i.e. __…☆12Updated 9 years ago
- a Ruby implementation of Java's ObjectInputStream and ObjectOutputStream.☆16Updated 2 years ago
- Extension adds a new tab in Burp Suite called Extractor☆42Updated 6 years ago
- DupeKeyInjector☆135Updated 3 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆50Updated 6 years ago