ambionics / scalpel
Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.
☆57Updated 9 months ago
Alternatives and similar repositories for scalpel:
Users that are interested in scalpel are comparing it to the libraries listed below
- Utility for creating ZipSlip archives☆71Updated 2 years ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆86Updated 11 months ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆83Updated 4 months ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- oauth-labs: an intentionally vulnerable set of OAuth 2.0 labs for security training and learning☆65Updated 3 months ago
- ☆87Updated 10 months ago
- Burp Suite's extension to scan and crawl Single Page Applications☆102Updated last year
- Make better use of the embedded browser that comes by default with Burp☆43Updated last year
- Nuclei Templates to reproduce Cracking the lens's Research☆124Updated 3 years ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆91Updated 9 months ago
- A project for fuzzing HTTP/1.1 CL.0 Request Smuggling Attack Vectors☆85Updated last year
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆118Updated last year
- ☆74Updated 5 months ago
- A (small) web exploit framework☆83Updated last month
- ☆34Updated 2 years ago
- tool that generates bypasses for open redirects☆52Updated 2 years ago
- A better way of querying certificate transparency logs☆84Updated 3 months ago
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)☆75Updated 9 months ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆61Updated 2 years ago
- ☆60Updated 2 years ago
- Burp Extension that copies a request and builds a FFUF skeleton☆111Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆26Updated last year
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆132Updated 8 months ago
- unleashed ffuf☆111Updated 8 months ago
- Burp Suite Extension - Trigger actions and reshape HTTP request/response and WebSocket traffic using configurable rules☆99Updated 4 months ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆75Updated last year
- A powerful AWS Cognito analysis and session hijacking toolkit designed for security researchers and penetration testers. CognitoHunter sp…☆20Updated 2 months ago
- A Python script to exploit CVE-2022-36446 Software Package Updates RCE (Authenticated) on Webmin < 1.997.☆112Updated last month
- A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.☆38Updated 4 months ago
- Gopher Tomcat Deployer☆48Updated 6 years ago