j0lt-github / python-deserialization-attack-payload-generator
Peas create serialized payload for deserialization RCE attack on python driven applications where pickle ,pyYAML, ruamel.yaml or jsonpickle module is used for deserialization of serialized data. I will update it with more attack vectors to targets other modules.
☆110Updated last year
Alternatives and similar repositories for python-deserialization-attack-payload-generator:
Users that are interested in python-deserialization-attack-payload-generator are comparing it to the libraries listed below
- This tool is for letting you know how strong your disable_functions is and how you can bypass that.☆128Updated 5 years ago
- Root shell PoC for CVE-2021-3156☆66Updated 4 years ago
- Damn Vulnerable Thick Client App developed in C# .NET☆152Updated last year
- Werkzeug has a debug console that requires a pin. It's possible to bypass this with an LFI vulnerability or use it as a local privilege e…☆57Updated 2 years ago
- A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection☆70Updated 4 years ago
- Phar + JPG Polyglot generator and playground (CTF CODE)☆88Updated 6 years ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆66Updated 2 years ago
- Python exploit for the CVE-2021-22204 vulnerability in Exiftool☆93Updated 3 years ago
- Python tool for enumerating directories and files on web servers that contain a publicly readable .ds_store file.☆58Updated 3 years ago
- SSTI Payload Generator☆90Updated 2 years ago
- Apache Spark Shell Command Injection Vulnerability☆87Updated 2 years ago
- Privilege escalation with polkit - CVE-2021-3560☆119Updated 3 years ago
- ☆118Updated 2 years ago
- Shell Simulation over Net-SNMP with extend functionality☆95Updated 4 years ago
- GameOver(lay) Ubuntu Privilege Escalation☆124Updated last year
- Windows Kernel Exploits☆66Updated 7 years ago
- Exploit for CVE-2021-3129☆65Updated 4 years ago
- Tool to enable blind sql injection attacks against websockets using sqlmap☆60Updated last week
- generate payloads that force authentication against an attacker machine☆106Updated 2 years ago
- Source Code Management Attack Toolkit☆218Updated 2 years ago
- Enumerate / Dump Docker Registry☆175Updated last year
- ☆160Updated 3 years ago
- POC for CVE-2022-47966 affecting multiple ManageEngine products☆126Updated 2 years ago
- Multi-threaded, IPv6 aware, wordlists/single-user username enumeration via CVE-2018-15473☆108Updated last year
- Repository to store exploits created by Assetnotes Security Research team☆177Updated last year
- POC for CVE-2020-13151☆30Updated 4 years ago
- The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.☆84Updated last year
- Herramientas y utilidades de pentesting, ethical hacking y seguridad ofensiva.☆36Updated last week
- ☆82Updated last month
- A Python based ingestor for BloodHound☆83Updated 2 years ago