iagox86 / poracle
☆89Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for poracle
- A Java serializer in JavaScript☆82Updated 6 years ago
- A front-end JavaScript toolkit for creating DNS rebinding attacks.☆45Updated 6 years ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆98Updated 5 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆34Updated 8 years ago
- Tests for different parsers from Ruby, Python, .NET, PHP, Perl, Java☆56Updated 8 years ago
- ☆70Updated 7 years ago
- ☆84Updated 7 years ago
- ☆45Updated 8 years ago
- Cracker for Apache.lang.commons RandomStringUtils(). Code for "The Java Soothsayer" talk at EkoParty 2017 by Alejo Popovici.☆32Updated 6 years ago
- Jaqen - Simple DNS rebinding☆71Updated 6 years ago
- Python Web framework P0wner☆75Updated 11 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆52Updated 11 years ago
- public exploits☆35Updated last year
- Java Deserialization☆26Updated 8 years ago
- Tool for CVE-2018-16323☆81Updated 5 years ago
- X41 BeanStack - Stack Trace Fingerprinting BETA☆52Updated 4 years ago
- ☆55Updated 6 years ago
- ImaegMagick Code Execution (CVE-2016-3714)☆68Updated 8 years ago
- Image size issues plugin for Burp Suite☆93Updated 6 years ago
- A brute force program to test weak accounts configured to access a JMX Registry☆33Updated 7 years ago
- Full TTY reverse shell over SSH☆57Updated 4 years ago
- A tool for detecting XML External Entity (XXE) vulnerabilities in Java applications☆72Updated 10 years ago
- Improved decoder for Burp Suite☆135Updated 3 years ago
- some example ctf writeups☆27Updated 4 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 10 years ago
- Demo server for testing Java deserialization payloads☆15Updated 8 years ago
- An example of obtaining RCE via Redis and CSRF☆77Updated 8 years ago
- Extension adds a new tab in Burp Suite called Extractor☆42Updated 5 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Updated 7 years ago