kh4sh3i / ElasticSearch-PentestingLinks
ElasticSearch exploit and Pentesting guide for penetration tester
☆30Updated 3 years ago
Alternatives and similar repositories for ElasticSearch-Pentesting
Users that are interested in ElasticSearch-Pentesting are comparing it to the libraries listed below
Sorting:
- A python3 script searching for secret on swaggerhub☆66Updated 3 years ago
- A BurpSuite extension to deploy an OpenVPN config file to DigitalOcean and set up a SOCKS proxy to route traffic through it☆51Updated 3 months ago
- Determine the running software version of a remote F5 BIG-IP management interface.☆69Updated 2 years ago
- ☆60Updated 3 years ago
- ☆27Updated 4 years ago
- The great Microsoft exchange hack: A penetration tester’s guide (exchange penetration testing)☆129Updated 5 months ago
- A Burp Suite extension for finding DNS vulnerabilities in web applications!☆92Updated 2 years ago
- ☆27Updated 2 years ago
- User enumeration and password spraying tool for testing Azure AD☆71Updated 3 years ago
- A "Spring4Shell" vulnerability scanner.☆49Updated last year
- ☆79Updated last week
- ☆34Updated last year
- Burp Extension to add additional functionality for pentesting websocket based applications☆103Updated 5 months ago
- Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers.☆48Updated 3 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Updated 3 years ago
- CoWitness is a powerful web application testing tool that enhances the accuracy and efficiency of your testing efforts. It allows you to …☆126Updated last year
- Nmapurls parses Nmap xml reports from either piped input or command line arg and outputs a list of http(s) URL's to be used in an automat…☆43Updated 7 months ago
- A fast enumeration tool for publicly exposed Azure Storage blobs.☆116Updated 2 years ago
- A Proof-Of-Concept for the CVE-2023-43770 vulnerability.☆33Updated 2 years ago
- Simple bash Script to automate initial recon using (httpx, puredns, regulator, wayback, katana, aquatone)☆34Updated 2 weeks ago
- ☆67Updated 2 years ago
- A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.☆106Updated 2 years ago
- Enumerate AWS permissions and resources.☆71Updated 3 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆31Updated 2 years ago
- SQLMap wrapper that lets you use Interact.sh as a DNS server for exfiltrating data with zero configuration☆45Updated 3 weeks ago
- ☆43Updated 2 years ago
- this script will help you find favicon hashes which you can use to shodan to get more details about an asset☆30Updated 10 months ago
- Proof of Concept for Path Traversal in Apache Struts ("CVE-2023-50164")☆57Updated 2 years ago
- ☆106Updated 3 years ago
- Just some random small tools for dealing with asp.net Forms Authentication Cookies☆30Updated 4 years ago