g3rzi / HackingKubernetes
This repository contain any information that can be used to hack Kubernetes
☆100Updated 2 years ago
Alternatives and similar repositories for HackingKubernetes:
Users that are interested in HackingKubernetes are comparing it to the libraries listed below
- Simple tool to decrypt Jenkins encrypted strings☆74Updated last year
- Nuclei templates for K8S security scanning☆101Updated 3 years ago
- Container Excape PoC for CVE-2022-0847 "DirtyPipe"☆77Updated 2 years ago
- Executes commands in a container on a kubelet endpoint that allows anonymous authentication (default)☆112Updated 6 years ago
- Source Code Management Attack Toolkit☆212Updated 2 years ago
- Static code analysis tool based on Elasticsearch☆129Updated 3 years ago
- Kubernetes POC for utilizing write mount to /var/log for getting a root on the host☆93Updated 4 years ago
- A fingerprint generation helper for nuclei network templates☆72Updated 2 years ago
- F5 BIG-IP RCE exploitation (CVE-2022-1388)☆88Updated 2 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆117Updated last year
- A robust Red Team proxy written in Go.☆161Updated 3 years ago
- CVE-2021-40346 PoC (HAProxy HTTP Smuggling)☆39Updated 3 years ago
- POC for CVE-2022-23648☆36Updated 2 years ago
- RmiTaste allows security professionals to detect, enumerate, interact and exploit RMI services by calling remote methods with gadgets fro…☆106Updated 4 years ago
- ☆154Updated 2 years ago
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆122Updated 2 years ago
- POC for CVE-2022-47966 affecting multiple ManageEngine products☆126Updated last year
- Shell Simulation over Net-SNMP with extend functionality☆93Updated 4 years ago
- Kubernetes pentesting, hardening and hunting tools.☆60Updated 2 years ago
- Utility for creating ZipSlip archives☆68Updated last year
- This is a dockerized application that is vulnerable to the Spring4Shell vulnerability (CVE-2022-22965).☆105Updated 2 years ago
- ☆27Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207☆108Updated last year
- Exploiting CVE-2021-44228 in VMWare Horizon for remote code execution and more.☆121Updated 3 years ago
- Spring Framework RCE (CVE-2022-22965) Nmap (NSE) Checker (Non-Intrusive)☆102Updated 2 years ago
- Command line tool for dumping Jenkins credentials.☆166Updated 5 months ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆54Updated last year
- Apache Spark Shell Command Injection Vulnerability☆87Updated 2 years ago
- CVE-2021-27928 MariaDB/MySQL-'wsrep provider' 命令注入漏洞☆61Updated last year