ezequielpereira / GAE-RCE
Google App Engine - Remote Code Execution bug ($36k bug bounty)
☆144Updated 6 years ago
Alternatives and similar repositories for GAE-RCE:
Users that are interested in GAE-RCE are comparing it to the libraries listed below
- psychoPATH - hunting file uploads & LFI in the dark. This tool is a customisable payload generator designed for blindly detecting LFI & w…☆141Updated 7 years ago
- The challenge source code and solutions for FBCTF 2019☆200Updated last year
- Chrome < 62 uxss exploit (CVE-2017-5124)☆161Updated 7 years ago
- Publicly released tools/plugins from PPP for DEFCON 25 CTF Finals☆140Updated 6 years ago
- ☆267Updated last year
- Stealing CSRF tokens with CSS injection (without iFrames)☆318Updated 6 years ago
- X41 Browser Security White Paper - Tools and PoCs☆184Updated 7 years ago
- Repo for CSAW CTF 2016 Quals challenges☆73Updated 8 years ago
- ☆167Updated 5 years ago
- Code and slides for Zer0Con 2018 talk: Building a 1-day Exploit for Google Chrome☆158Updated 6 years ago
- An information gathering tool to collect git commit emails in version control host services☆153Updated 5 years ago
- A command line Hash Identifying tool.☆101Updated 5 years ago
- Proof-of-concept program that is able to to hijack/hook/proxy Python module(s) thanks to $PYTHONPATH variable☆151Updated 7 years ago
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- ☆132Updated 9 years ago
- A database of published security advisories reported by the Programa STIC Team at Fundación Sadosky☆87Updated 7 years ago
- PLASMA PULSAR☆69Updated 7 years ago
- ☆89Updated 6 years ago
- A Pwn2Own exploit chain☆757Updated 6 years ago
- ☆170Updated 3 years ago
- A Go implementation of the BERserk attack against Mozilla NSS ASN.1 parsing of PKCS#1 RSA signatures with e = 3. Complete of a certificat…☆94Updated 9 years ago
- A list of publicly known but unfixed security bugs☆237Updated 6 years ago
- Running CVE-2017-8759 exploit sample.☆255Updated 5 years ago
- ☆29Updated 5 years ago
- ☆72Updated 5 years ago
- 35C3 Junior CTF pwnables☆148Updated 6 years ago
- ☆235Updated 5 years ago
- Runtime memory analysis framework to identify Android malware☆144Updated 6 years ago
- Simple test for the May 2016 OpenSSL padding oracle (CVE-2016-2107)☆186Updated 5 years ago
- Writeups for CTF competitions.☆32Updated 8 years ago