mveytsman / dilettante
Maven central doesn't do SSL when serving you JARs. Dilettante is a MiTM proxy for exploiting that.
☆159Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for dilettante
- Java Agent which mitigates deserialisation attacks by making certain classes unserializable☆185Updated 8 years ago
- JMSDigger is JMS API basedEnterprise Messaging Application assessment tool☆31Updated 10 years ago
- Mass scanner for the Java serialize bug☆149Updated 5 years ago
- A practical tool for bytecode manipulation and creating Managed Code Rootkits (MCRs) in the Java Runtime Environment☆57Updated 4 years ago
- ☆128Updated 8 years ago
- Demo Application and Exploit☆35Updated 7 years ago
- Primitive tool for exploring/querying Java classes via the Tinkerpop Gremlin graph traversal language☆104Updated 8 years ago
- Improved decoder for Burp Suite☆135Updated 3 years ago
- Burp Suite extension to generate Intruder payloads using Radamsa☆87Updated 7 years ago
- Image size issues plugin for Burp Suite☆93Updated 6 years ago
- Jaqen - Simple DNS rebinding☆71Updated 6 years ago
- Identify vulnerable libraries in Maven dependencies☆45Updated last year
- TLS Redirection☆118Updated 7 years ago
- Burp extension to perform Java Deserialization Attacks☆208Updated 9 months ago
- A regex based source code scanner.☆128Updated 7 years ago
- burpbuddy exposes Burp Suites's extender API over the network through various mediums, with the goal of enabling development in any langu…☆156Updated 5 years ago
- GPG Reaper - Obtain/Steal/Restore GPG Private Keys from gpg-agent cache/memory☆92Updated 6 years ago
- ☆96Updated 3 years ago
- A library to assist in security-testing Unicode enabled applications during fuzzing, XSS, SQLi, etc.☆42Updated 7 years ago
- Externalize Java application access to protected resources as log messages.☆41Updated 6 months ago
- Some scripts and exploits☆142Updated 6 years ago
- The Guppy Proxy (GUI Pappy)☆144Updated 5 years ago
- An example of obtaining RCE via Redis and CSRF☆77Updated 8 years ago
- A tiny Java agent that blocks attacks against unsafe deserialization☆83Updated 7 years ago
- A security tool to fingerprint PNG libraries used by web applications☆80Updated 5 years ago
- A set of tools made to assist in penetration testing GWT applications. Additional details about these tools can be found on my OWASP Apps…☆225Updated 4 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 10 years ago
- Cracker for Apache.lang.commons RandomStringUtils(). Code for "The Java Soothsayer" talk at EkoParty 2017 by Alejo Popovici.☆32Updated 6 years ago