jpiechowka / zip-shotgunLinks
Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)
☆32Updated 6 years ago
Alternatives and similar repositories for zip-shotgun
Users that are interested in zip-shotgun are comparing it to the libraries listed below
Sorting:
- AWS S3 Bucket/Object Finder☆24Updated 7 years ago
- An enumeration and exploitation toolkit using RFC calls to SAP☆38Updated 5 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- A Pythonic wrapper to MassDNS☆24Updated 7 years ago
- Samba, NFS shares spider and grepper☆71Updated 7 years ago
- Burp extension to decode NTLM SSP headers and extract domain/host information☆32Updated 4 years ago
- This repo will contain slides and information from the Attacking Active Directory Hacking Series talks presented at SecKC.☆32Updated last year
- A Burp Suite content discovery plugin that add the smart into the Buster!☆31Updated 7 years ago
- automatic scan for hackthebox☆13Updated 5 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- Data exfiltration utility for testing detection capabilities☆57Updated 3 years ago
- ☆20Updated 5 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Updated 4 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- Purpose of this repository is to help all the beginner and experienced professionals to understand,learn and share new tricks for the com…☆32Updated 7 years ago
- Basic tool to automate backdooring PE files☆56Updated 3 years ago
- Just a silly recon tool that uses data from SSL Certificates to find potential host names☆30Updated 2 years ago
- Alphanumeric Encoder☆25Updated 6 years ago
- miscellaneous stuff☆21Updated 10 years ago
- API testing tool written with Python☆56Updated 8 years ago
- Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510☆18Updated 5 years ago
- ☆24Updated 6 months ago
- Tooling and commands for common red team and Infrastructure testing tasks☆43Updated 2 years ago
- ☆92Updated 2 years ago
- Vulnerable webapp testbed☆21Updated 9 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆54Updated 4 years ago
- A threaded, recursive, web directory brute-force scanner over HTTP/2.☆36Updated 5 years ago
- A simple grep user interface for searching code which can be used for SAST.☆8Updated 5 years ago
- A basic AIX enumeration guide for penetration testers/red teamers☆32Updated 8 years ago
- Oracle Database Penetration Testing Reference (10g/11g)☆36Updated 6 years ago