pentagridsec / archive_pwn
A Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes
☆43Updated last year
Alternatives and similar repositories for archive_pwn:
Users that are interested in archive_pwn are comparing it to the libraries listed below
- Additional active scan checks for BURP☆27Updated 7 months ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆47Updated 7 months ago
- An Evil OIDC Server☆53Updated 2 years ago
- ☆17Updated 2 years ago
- ☆64Updated last week
- List of fresh and validated DNS resolvers updated every 12h.☆22Updated this week
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated 2 months ago
- ☆28Updated last year
- ☆26Updated 2 years ago
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 3 years ago
- A set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate in as simple a p…☆30Updated 3 months ago
- ☆27Updated 2 years ago
- Python script to launch burp scans automatically☆32Updated 3 years ago
- Take domains on stdin and output them on stdout if they get resolved☆33Updated 2 years ago
- ☆16Updated 5 months ago
- Finding sensitive information in the trimmed parts of cropped images☆29Updated 3 years ago
- Check robustness of your (their) Active Directory accounts passwords☆35Updated 2 months ago
- dauthi is a tool that takes advantage of API functionality across a variety of MDM solutions to perform user enumeration and single-facto…☆41Updated last year
- cvet is a Python utility for pulling actionable vulnerabilities from cvetrends.com☆39Updated 2 years ago
- ☆23Updated 2 years ago
- Exploits Unauth Docker API☆40Updated 2 weeks ago
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆32Updated 2 years ago
- self-hosted Azure OSINT tool☆30Updated 8 months ago
- Ffuf output browser☆39Updated 2 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆71Updated 3 years ago
- HazProne is a Cloud Pentesting Framework that emulates close to Real-World Scenarios by deploying Vulnerable-By-Demand AWS resources enab…☆39Updated 2 years ago
- FireProx written in Go☆19Updated last year
- A tool to parse, deduplicate, and query multiple port scans.☆59Updated last year
- CRLFMap is a tool to find HTTP Splitting vulnerabilities☆25Updated 4 years ago
- Manage attack surface data on Elasticsearch☆22Updated last year