Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.
☆245Oct 8, 2024Updated last year
Alternatives and similar repositories for wrapwrap
Users that are interested in wrapwrap are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()☆504Sep 30, 2024Updated last year
- A CLI to exploit parameters vulnerable to PHP filter chain error based oracle.☆333Jun 2, 2024Updated 2 years ago
- ☆1,071Jan 23, 2023Updated 3 years ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆116Jun 23, 2025Updated last year
- ☆352Jan 24, 2023Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,890Sep 29, 2025Updated 11 months ago
- A (small) web exploit framework☆98Dec 26, 2025Updated 8 months ago
- dotnet 反序列化学习笔记☆523Oct 19, 2023Updated 2 years ago
- Some ReadObject Sink With JDBC☆243May 8, 2024Updated 2 years ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆92Mar 25, 2024Updated 2 years ago
- Java RMI Vulnerability Scanner☆932Sep 3, 2026Updated 2 weeks ago
- Coffee is a loader for ELF (Executable and Linkable Format) object files written in Rust. Coffee是一个用Rust语言编写的ELF object文件的加载器☆61Apr 29, 2024Updated 2 years ago
- 抽离出 utf-8-overlong-encoding 的序列化逻辑,实现 2 3 字节加密序列化数组☆141Mar 11, 2024Updated 2 years ago
- ☆97Aug 28, 2026Updated 3 weeks ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- 构造字节在ASCII范围内的jar☆141Feb 14, 2022Updated 4 years ago
- 一款使用Yaml定义搜索规则来搜索Class的工具☆107Aug 2, 2023Updated 3 years ago
- cve-2022-34169 延伸出的Jdk Xalan的payload自动生成工具,可根据不同的Jdk生成出其所对应的xslt文件☆93Jan 17, 2023Updated 3 years ago
- Prototype Pollution and useful Script Gadgets☆1,649Jan 27, 2024Updated 2 years ago
- Topic: The Swiss Army Knife of Java Exploitation☆22Feb 25, 2025Updated last year
- This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) an…☆150Feb 4, 2026Updated 7 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆240Feb 6, 2025Updated last year
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆116Mar 27, 2024Updated 2 years ago
- ☆50Dec 4, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- CTF challenges I created 🚩☆87Mar 7, 2026Updated 6 months ago
- A small utility to translate NTDS.dit files to SQLite format.☆85Oct 11, 2023Updated 2 years ago
- some fun php exploits☆81Nov 12, 2024Updated last year
- A neo4j procedure for tabby☆134May 17, 2025Updated last year
- PoC for CVE-2023-4911☆394Oct 4, 2023Updated 2 years ago
- attachments and (some) writeups/source code for RWCTF 6th☆126Feb 2, 2024Updated 2 years ago
- Burp Suite extension that mutates ciphers to bypass TLS-fingerprint based bot detection☆501Sep 9, 2025Updated last year
- Powerview on steroids☆998Sep 3, 2026Updated 2 weeks ago
- A rouge mysql server supports reading files from most mysql libraries of multiple programming languages.☆774Dec 2, 2022Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Find all libraries on cdn.js that pollute your prototype☆19Sep 1, 2022Updated 4 years ago
- Escalate Service Account To LocalSystem via Kerberos☆404Sep 14, 2023Updated 3 years ago
- BloodyAD is an Active Directory Privilege Escalation Framework☆2,301Updated this week
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆507Jan 12, 2026Updated 8 months ago
- awd/awdp 小工具,使用 javassist 对 jar 包进行 patch☆32Nov 9, 2023Updated 2 years ago
- CVE-2024-41570: Havoc C2 0.7 Teamserver SSRF exploit☆76Sep 11, 2024Updated 2 years ago
- PaddingZip is a tool that you can craft a zip file that contains the padding characters between the file content.☆81Aug 14, 2022Updated 4 years ago