georlav / objectmap
A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.
☆24Updated 5 years ago
Alternatives and similar repositories for objectmap
Users that are interested in objectmap are comparing it to the libraries listed below
Sorting:
- HTTP Desync Attack☆28Updated 5 years ago
- ☆17Updated 2 years ago
- My fuzzing workshop from PHDays9☆26Updated 5 years ago
- A python-based padding oracle tool☆20Updated 9 months ago
- Compiled dataset of Java deserialization CVEs☆61Updated 4 years ago
- Burp extension to generate multi-step CSRF POC.☆30Updated 5 years ago
- PoC for CVE-2020-8617 (BIND)☆45Updated 4 years ago
- OWASP ZAP add-on to detect reflected parameter vulnerabilities efficiently☆12Updated 4 years ago
- burp extender for fuzzing☆10Updated 6 years ago
- RAS(RAndom Subdomain) Fuzzer☆42Updated 5 years ago
- Lab that will help you to understand how type juggling vulnerability works.☆22Updated 4 years ago
- A collection of utilities to simplify the creation of Burp Suite plugins☆22Updated last year
- ☆37Updated 4 years ago
- Burp Suite extension for Radamsa-powered fuzzing with Intruder☆20Updated 3 years ago
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆12Updated last year
- ☆24Updated last year
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆76Updated 4 years ago
- Burp Extension for copying requests safely. It redacts headers like Cookie, Authorization and X-CSRF-Token for now. More support can be a…☆17Updated 5 years ago
- Insecure Deserialization, PDF and lab☆18Updated 5 years ago
- Query various sources for CVE proof-of-concepts☆51Updated last year
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆33Updated 6 years ago
- ☆71Updated 3 years ago
- Study about HQL injection exploitation.☆51Updated 9 years ago
- String or worldlist encoder for use in fuzzing or web application testing☆19Updated 5 years ago
- CVE-2019-9580 - StackStorm: exploiting CORS misconfiguration (null origin) to gain RCE☆32Updated 6 years ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆19Updated 4 years ago
- My custom semgrep rules☆21Updated 4 years ago
- ☆1Updated 4 years ago
- XSS payloads for edge cases☆34Updated 6 years ago
- a Ruby implementation of Java's ObjectInputStream and ObjectOutputStream.☆16Updated 2 years ago