ambionics / scalpel
Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.
☆52Updated 5 months ago
Related projects ⓘ
Alternatives and complementary repositories for scalpel
- Utility for creating ZipSlip archives☆67Updated last year
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆60Updated 2 weeks ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆86Updated 7 months ago
- Improve automated and semi-automated active scanning in Burp Pro☆60Updated 2 years ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆85Updated 9 months ago
- ☆80Updated 6 months ago
- A (small) web exploit framework☆81Updated last month
- ☆30Updated last year
- Burp Suite's extension to scan and crawl Single Page Applications☆99Updated last year
- The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.☆65Updated 8 months ago
- Gopher Tomcat Deployer☆47Updated 6 years ago
- ☆65Updated last month
- This repository contains all the examples related to a series of tutorials that demonstrate how to use the new Montoya API of Burp Suite …☆35Updated this week
- tool that generates bypasses for open redirects☆49Updated 2 years ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆84Updated 5 months ago
- ☆56Updated last year
- Dockerized POC for CVE-2022-42889 Text4Shell☆75Updated 2 years ago
- ☆24Updated 5 months ago
- unleashed ffuf☆96Updated 4 months ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆107Updated 4 months ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆60Updated last year
- jolokia-exploitation-toolkit☆281Updated 8 months ago
- ☆24Updated 2 years ago
- Repository to store exploits created by Assetnotes Security Research team☆174Updated last year
- Nuclei Templates to reproduce Cracking the lens's Research☆121Updated 2 years ago
- Exploit for CVE-2024-20767 - Adobe ColdFusion☆33Updated 7 months ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆25Updated 9 months ago
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆73Updated last month
- A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.☆110Updated 2 years ago
- Burp Suite Extension - Trigger actions and reshape HTTP request/response and WebSocket traffic using configurable rules☆92Updated 2 weeks ago