pimps / JNDI-Exploit-Kit
JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps vulnerable to JNDI Injection)
☆913Updated 3 years ago
Alternatives and similar repositories for JNDI-Exploit-Kit:
Users that are interested in JNDI-Exploit-Kit are comparing it to the libraries listed below
- A malicious LDAP server for JNDI injection attacks☆1,028Updated last year
- Log4j jndi injects the Payload generator☆487Updated 3 years ago
- 🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks☆934Updated 3 years ago
- Log4Shell scanner for Burp Suite☆483Updated last year
- RCE 0-day for GhostScript 9.50 - Payload generator☆542Updated 3 years ago
- Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user☆1,003Updated 2 years ago
- Java RMI Vulnerability Scanner☆851Updated 8 months ago
- A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.☆398Updated 2 months ago
- log4j rce test environment and poc☆310Updated 3 years ago
- CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.☆1,360Updated 3 years ago
- HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907☆361Updated 3 years ago
- Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965☆362Updated 2 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆596Updated 3 years ago
- Log4Shell RCE Exploit - fully independent exploit does not require any 3rd party binaries.☆258Updated 3 years ago
- WSO2 RCE (CVE-2022-29464) exploit and writeup.☆369Updated 2 years ago
- Sudo Baron Samedit Exploit☆742Updated 3 years ago
- A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)☆583Updated last year
- Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)☆783Updated 3 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆851Updated 3 years ago
- Burpsuite extension for log4j2rce☆28Updated 3 years ago
- Grafana Unauthorized arbitrary file reading vulnerability☆356Updated 2 years ago
- HTTP Request Smuggling over HTTP/2 Cleartext (h2c)☆704Updated 2 years ago
- Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user☆846Updated 2 years ago
- Windows Privilege Escalation from User to Domain Admin.☆1,363Updated 2 years ago
- RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities☆429Updated 2 years ago
- JMX enumeration and attacking tool.☆420Updated last month
- JSshell - JavaScript reverse/remote shell☆617Updated 2 years ago
- A proof of concept exploit for CVE-2022-40684 affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager☆349Updated 2 years ago
- A python script to scan for Apache Tomcat server vulnerabilities.☆816Updated 2 weeks ago
- ☆557Updated 3 years ago