p4k03n4t0r / http-request-smugglingLinks
Blog about HTTP Request Smuggling, including a demo application.
☆32Updated 4 years ago
Alternatives and similar repositories for http-request-smuggling
Users that are interested in http-request-smuggling are comparing it to the libraries listed below
Sorting:
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 3 years ago
- ☆29Updated 3 years ago
- Same Origin XSS challenge☆64Updated 3 years ago
- Security Advisories☆35Updated 2 months ago
- A collection of utilities for building extensions using Burp's Montoya API☆52Updated 2 months ago
- ☆170Updated 4 years ago
- ☆42Updated 2 months ago
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆28Updated 7 years ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆109Updated 6 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆35Updated 10 months ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆71Updated 2 years ago
- CVE-2022-21907 Vulnerability PoC☆30Updated 3 years ago
- Prototype Pollution exploits collection☆37Updated 4 years ago
- Make better use of the embedded browser that comes by default with Burp☆44Updated 2 years ago
- Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.☆66Updated last year
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆114Updated last year
- HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets☆35Updated 3 years ago
- A collection of Burp Suite Lambda Filters ~ Bambdas☆30Updated last year
- Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)☆88Updated 3 years ago
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆91Updated last year
- This repo contains solution for ctf challenges☆38Updated last year
- WordPress - Authenticated XXE (CVE-2021-29447)☆43Updated 4 years ago
- Improve automated and semi-automated active scanning in Burp Pro☆63Updated 7 months ago
- Awesome MXSS ??☆56Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆34Updated last year
- CTF, wargame cheatsheet☆32Updated 7 years ago
- ☆56Updated 4 years ago
- Utility for creating ZipSlip archives☆80Updated 2 years ago
- ☆25Updated 10 months ago
- Burp Extension that copies a request and builds a FFUF skeleton☆112Updated 2 years ago