nemo-wq / privilege_escalationLinks
Lab exercises to practice privilege escalation scenarios in AWS IAM. These exercises and the slides go through the basics behind AWS IAM, common weaknesses in AWS deployments, specific to IAM, and how to exploit them manually. This was run as a workshop at BruCon 2019.
☆16Updated 5 years ago
Alternatives and similar repositories for privilege_escalation
Users that are interested in privilege_escalation are comparing it to the libraries listed below
Sorting:
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- Slides of the talk on Injection attacks in apps with NoSQL Backends, given at null OWASP Bangalore monthly meet on 27th April 2019☆22Updated 6 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆31Updated 7 years ago
- Collection of different exploitation scenarios of JWT.☆21Updated 3 years ago
- Scripts for OSCE☆18Updated 6 years ago
- ☆38Updated 4 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- A Pythonic wrapper to MassDNS☆24Updated 7 years ago
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- AWS S3 Bucket/Object Finder☆24Updated 7 years ago
- A simple grep user interface for searching code which can be used for SAST.☆8Updated 5 years ago
- ☆36Updated 5 years ago
- Pythonize Intruder Payload☆13Updated 4 years ago
- Yet another open S3 bucket finder☆20Updated 7 years ago
- A collection of OSCE preparation resources.☆24Updated 5 years ago
- ☆14Updated 5 years ago
- Journey to conquer the OSCP!☆13Updated 6 years ago
- Pivot into private VPC networks using a VPN connection☆42Updated 5 years ago
- Alpha version code of Recon UI☆14Updated 7 years ago
- LetMeOutOfYour.net Resources☆20Updated 4 years ago
- ☆10Updated 6 years ago
- Python tool for expired domain discovery in crossdomain.xml files☆23Updated 8 years ago
- ☆32Updated 6 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆26Updated 6 years ago
- PHP tool to test XSS☆22Updated 5 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Updated 4 years ago
- This changes the style of Burp Suite's Repeater tabs to help the testers☆29Updated 5 years ago
- An enumeration and exploitation toolkit using RFC calls to SAP☆38Updated 5 years ago
- ☆20Updated 5 years ago
- View screenshots as a slideshow over http☆15Updated 5 years ago