cschneider4711 / DeserializationExercises
☆12Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for DeserializationExercises
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆24Updated 5 years ago
- All about CVE-2018-14667; From what it is to how to successfully exploit it.☆49Updated 5 years ago
- Parse X509 certificates to get the (sub)domains in it.☆28Updated 6 years ago
- Burp Suite plugin that allow to deserialize Java objects and convert them in an XML format. Unpack also gzip responses. Based on BurpJDSe…☆20Updated 9 months ago
- ☆35Updated 4 years ago
- Burp plugin to do random fuzzing of HTTP requests☆33Updated 7 years ago
- Study about HQL injection exploitation.☆49Updated 8 years ago
- A collection of published exploits and proof-of-concept code.☆20Updated 6 years ago
- A tool to analyse JMX API security level.☆43Updated 10 years ago
- Proof of concept written in Python to show that in some situations a SSRF vulnerability can be used to steal NTLMv1/v2 hashes.☆57Updated 6 years ago
- Unified repository for different Metasploit Framework payloads☆47Updated 4 years ago
- Demonstrating why Dynamic Method Invocation with unrestricted method names (the old default of Struts) is dangerous.☆12Updated 6 years ago
- OWASP Skanda - SSRF Exploitation Framework☆36Updated 11 years ago
- Utilities for creating Burp Suite Extensions.☆21Updated 3 weeks ago
- Nashorn Post Exploitation☆31Updated 6 years ago
- Another plugin for CRLF vulnerability detection☆26Updated 7 years ago
- RCE Exploit PoC for Spring based RESTFul APIs using XStream as Unmarshaler☆20Updated 10 years ago
- cve-2014-0130 rails directory traversal vuln☆18Updated 7 years ago
- Confluence Widget Connector path traversal (CVE-2019-3396)☆22Updated 5 years ago
- A quick and dirty .NET "Deserialize_*" fuzzer based on James Forshaw's (@tiraniddo) DotNetToJScript.☆42Updated 6 years ago
- Python tool for expired domain discovery in crossdomain.xml files☆22Updated 7 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆16Updated 11 years ago
- DoS PoC's for SAP products☆48Updated 6 years ago
- Automate SSH communication with firewalls, switches, etc.☆26Updated 6 years ago
- public exploits☆35Updated last year
- some example ctf writeups☆27Updated 4 years ago
- Python script to exploit CVE-2015-4852.☆30Updated 8 years ago