jpiechowka / zip-shotgun
Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)
☆32Updated 5 years ago
Alternatives and similar repositories for zip-shotgun
Users that are interested in zip-shotgun are comparing it to the libraries listed below
Sorting:
- An enumeration and exploitation toolkit using RFC calls to SAP☆38Updated 5 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- AWS S3 Bucket/Object Finder☆24Updated 7 years ago
- Any presentation we've given at FortyNorth Security☆34Updated 3 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- Just a simple SMTP server, implementation of @corpix smtpd library☆15Updated 5 years ago
- A collection of OSCE preparation resources.☆24Updated 5 years ago
- Vulnerable webapp testbed☆21Updated 9 years ago
- JavaScript functions intended to be used as an XSS payload against a WordPress admin account.☆54Updated 4 years ago
- Basic tool to automate backdooring PE files☆55Updated 3 years ago
- This repo will contain slides and information from the Attacking Active Directory Hacking Series talks presented at SecKC.☆32Updated 10 months ago
- Capture all RabbitMQ messages being sent through a broker.☆31Updated 4 years ago
- Data exfiltration utility for testing detection capabilities☆57Updated 3 years ago
- ☆20Updated 5 years ago
- Burp extension to decode NTLM SSP headers and extract domain/host information☆31Updated 4 years ago
- CVE-2018-18368 SEP Manager EoP Exploit☆17Updated 5 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆31Updated 7 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Updated 4 years ago
- A Pythonic wrapper to MassDNS☆24Updated 7 years ago
- automatic scan for hackthebox☆13Updated 5 years ago
- Alphanumeric Encoder☆25Updated 6 years ago
- Checklist for pentests, handy commands for to remembers, and a few tools to work on here and there. Far from complete!☆26Updated last year
- miscellaneous stuff☆21Updated 10 years ago
- Slides of the talk on Injection attacks in apps with NoSQL Backends, given at null OWASP Bangalore monthly meet on 27th April 2019☆22Updated 6 years ago
- Purpose of this repository is to help all the beginner and experienced professionals to understand,learn and share new tricks for the com…☆31Updated 7 years ago
- ☆23Updated 4 years ago
- UglyEXe - bypass some AVs☆17Updated 5 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- A basic AIX enumeration guide for penetration testers/red teamers☆32Updated 8 years ago
- Methods of C2☆21Updated 9 years ago