devploit / XORpass
Encoder to bypass WAF filters using XOR operations.
☆251Updated 2 years ago
Alternatives and similar repositories for XORpass:
Users that are interested in XORpass are comparing it to the libraries listed below
- Scan Victim Backup Directories & Backup Files☆178Updated last year
- CVE-2020–14882、CVE-2020–14883☆283Updated 4 years ago
- exploit CVE-2019-7609(kibana RCE) on right way by python2 scripts☆159Updated last year
- Bypassing WAF by abusing SSL/TLS Ciphers☆312Updated 3 years ago
- That repository contains my updates to the well know java deserialization exploitation tool ysoserial.☆176Updated 2 years ago
- Exporter is a Burp Suite extension to copy a request to a file or the clipboard as multiple programming languages functions.☆174Updated 3 years ago
- ☆127Updated 3 years ago
- SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities☆181Updated 4 years ago
- ☆181Updated last year
- CVE-2019-19781 - Remote Code Execution on Citrix ADC Netscaler exploit☆155Updated 4 years ago
- An Out-of-Band XXE server for retrieving file contents over FTP.☆178Updated 4 years ago
- jsubfinder searches webpages for javascript & analyzes them for hidden subdomains and secrets (wip).☆267Updated last month
- Toolkit to detect and keep track on Blind XSS, XXE & SSRF☆295Updated 5 years ago
- ☆281Updated 3 years ago
- This is a burp plugin that extracts keywords from response using regexes and test for reflected XSS on the target scope.☆76Updated 4 years ago
- ☆214Updated 2 years ago
- HTTP file upload scanner for Burp Proxy☆487Updated last year
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆570Updated 4 years ago
- Another way to bypass WAF Cheat Sheet (draft)☆421Updated 6 years ago
- ☆205Updated 3 years ago
- Exploit for Drupal 7 <= 7.57 CVE-2018-7600☆132Updated 6 years ago
- the only php webshell you need.☆224Updated 2 months ago
- Exploit for WebSocket Vulnerability in Apache Tomcat☆166Updated 4 years ago
- A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.☆514Updated 4 years ago
- Data extraction tool for Docker Registry API☆125Updated last year
- JWT Support for Burp☆113Updated 6 months ago
- PoC collection of Atlassian(Jira, Confluence, Bitbucket) products and Jenkins, Solr, Nexus☆174Updated 9 months ago
- cve-2020-0688☆322Updated last year
- SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.☆87Updated last year
- Ghazi is a BurpSuite Plugins For Testing various PayLoads Like "XSS,SQLi,SSTI,SSRF,RCE and LFI" through Different tabs , Where Each Tab W…☆110Updated 6 years ago