hakivvi / ObjectPwnStreamLinks
a Ruby implementation of Java's ObjectInputStream and ObjectOutputStream.
☆16Updated 3 years ago
Alternatives and similar repositories for ObjectPwnStream
Users that are interested in ObjectPwnStream are comparing it to the libraries listed below
Sorting:
- Query various sources for CVE proof-of-concepts☆52Updated 2 years ago
- ☆13Updated 2 years ago
- PoC CVE-2020-6308☆36Updated 4 years ago
- A Burp Suite extension to add a custom header (e.g. JWT)☆19Updated 3 years ago
- Gopher Tomcat Deployer☆48Updated 7 years ago
- 该脚本为Citrix XenMobile 目录遍历漏洞(CVE-2020-8209)批量检测脚本。☆31Updated 4 years ago
- Hacking Artifactory with server side template injection☆51Updated 5 years ago
- A Burp extension to show the Collaborator client in a tab☆24Updated 2 years ago
- Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.☆48Updated 4 years ago
- POC which exploits a vulnerability within Nagios XI (5.6.5) to spawn a root shell☆13Updated 4 years ago
- A python-based padding oracle tool☆20Updated last year
- Wordlist to get files/ folders listed by the app that may expose passwords, sensitive file or folders☆22Updated 5 years ago
- HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets☆35Updated 3 years ago
- RCE in NPM VSCode Extension☆20Updated 4 years ago
- Webshell for Razor Syntax (C#)☆19Updated 8 years ago
- Writeup of CVE-2020-15906☆49Updated 5 years ago
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆77Updated 5 years ago
- ☆53Updated 4 years ago
- SSRF to TCP Port Scanning, Banner and Private IP Disclosure by abusing the FTP protocol/clients☆70Updated 4 years ago
- POC Script for CVE-2020-12800: RCE through Unrestricted File Type Upload☆27Updated 2 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆40Updated 4 years ago
- Burp extension to generate multi-step CSRF POC.☆31Updated 6 years ago
- Exploit code for CVE-2020-11579, an arbitrary file disclosure through the MySQL client in PHPKB☆24Updated last year
- ☆36Updated 9 months ago
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆15Updated 2 years ago
- CVE-2020-13942 unauthenticated RCE POC through MVEL and OGNL injection☆28Updated 4 years ago
- A malicious LDAP server for JNDI injection attacks☆75Updated last year
- MySQL Injection Exfoliation Optimization☆24Updated 6 years ago
- Some payloads of JNDI Injection in JDK 1.8.0_191+☆10Updated 5 years ago
- miscellaneous security research stuff☆37Updated 6 years ago