federicodotta / ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
☆43Updated 5 years ago
Alternatives and similar repositories for ysoserial
Users that are interested in ysoserial are comparing it to the libraries listed below
Sorting:
- Python3 tool to perform password spraying against Microsoft Online service using various methods☆87Updated 2 years ago
- This code was used for the blogpost on secjuice.☆42Updated 6 years ago
- Powershell module to get the NetNTLMv2 hash of the current user☆93Updated 2 years ago
- Checks for signature requirements over LDAP☆97Updated 2 years ago
- Exchangelib wrapper for pentesting☆64Updated 2 months ago
- A list of "secrets" from JWT sample code and readme files.☆55Updated 4 years ago
- Add SD for controlled computer object to a target object for RBCD using LDAP☆38Updated 3 years ago
- Use normal web pentest tools to hack Websockets☆18Updated 5 years ago
- ☆17Updated 4 years ago
- ☆45Updated 8 years ago
- A Red Team tool for exfiltrating sensitive data from Confluence pages.☆112Updated 2 years ago
- Loads a custom dll in system32 via diaghub.☆74Updated 5 years ago
- Parse NTLM challenge messages over HTTP and SMB☆146Updated 2 years ago
- Example Vulnerable .NET HTTP Remoting☆84Updated 6 years ago
- A tool for creating proxy dll for hijacking☆42Updated 6 months ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆23Updated 5 years ago
- Jenkins pre-auth RCE exploit. More info at https://jenkins.io/security/advisory/2019-01-08/#SECURITY-1266 https://blog.orange.tw/2019/02/…☆10Updated 6 years ago
- A tool to password spray Jenkins instances☆56Updated 5 years ago
- Ruby script that calls an almost interactive shell via WinRM (TCP/5985) on an Windows machine, relaying on a valid Kerberos ticket. (Very…☆18Updated 5 years ago
- A python Flask app that generates dynamic DTDs for easy out-of-band data exfiltration.☆30Updated 2 years ago
- ☆9Updated 3 years ago
- This tool implements a cloud version of the Shadow Copy attack against domain controllers running in AWS using only the EC2:CreateSnapsho…☆120Updated 5 years ago
- ☆36Updated 4 years ago
- ☆128Updated last year
- A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.☆90Updated last year
- ☆51Updated 2 years ago
- Tool to discover Resource-Based Constrained Delegation attack paths in Active Directory environments☆122Updated 3 years ago
- A mirror of several precompiled standalone red-teaming tools.☆19Updated 2 years ago
- ☆39Updated 6 years ago
- Password Spraying Script detecting current and previous passwords of Active Directory User☆65Updated 3 years ago