kurobeats / fimap
fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.
☆525Updated 2 years ago
Alternatives and similar repositories for fimap:
Users that are interested in fimap are comparing it to the libraries listed below
- BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source c…☆539Updated 2 years ago
- Local file inclusion exploitation tool☆813Updated last year
- kadimus is a tool to check and exploit lfi vulnerability.☆521Updated 4 years ago
- ReverShellGenerator - A tool to generate various ways to do a reverse shell☆558Updated 8 months ago
- Simple php reverse shell implemented using binary .☆402Updated last year
- A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.☆962Updated 7 years ago
- A unique automated LFi Exploiter with Bind/Reverse Shells☆269Updated 9 years ago
- DotDotPwn - The Directory Traversal Fuzzer☆1,004Updated 2 years ago
- Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT☆393Updated 5 months ago
- A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, al…☆1,211Updated last year
- This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack☆684Updated last year
- RSMangler will take a wordlist and perform various manipulations on it similar to those done by John the Ripper with a few extras.☆216Updated 5 years ago
- Search for Directory Traversal Vulnerabilities☆421Updated 6 months ago
- Herramienta para evadir disable_functions y open_basedir☆401Updated last year
- Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner☆1,730Updated 2 years ago
- This repository contains all the supplement material for the book "The art of sub-domain enumeration"☆638Updated 5 years ago
- Wordlists that have been compiled using Commonspeak2. This repo is updated every time new wordlists are generated.☆522Updated 6 years ago
- Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and us…☆569Updated 6 months ago
- Username tools for penetration testing☆912Updated 3 months ago
- Finds unknown classes of injection vulnerabilities☆643Updated last year
- Content discovery wordlists generated using BigQuery☆562Updated 4 years ago
- Open Redirect Payloads☆594Updated 3 months ago
- A simple web app with a XXE vulnerability.☆225Updated 3 years ago
- Exploitation for XSS☆708Updated 3 years ago
- A script to enumerate virtual hosts on a server.☆669Updated 7 years ago
- A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessible Apache server-s…☆433Updated 3 years ago
- A small tool that extracts relative URLs from a file.☆738Updated 4 years ago
- Automated script for performing Padding Oracle attacks☆757Updated 6 months ago
- Modified version of the passing-the-hash tool collection made to work straight out of the box☆565Updated 9 years ago
- Collection of things made during my OSCP journey☆255Updated 7 years ago