pimps / JNDI-Exploit-Kit
JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps vulnerable to JNDI Injection)
☆918Updated 3 years ago
Alternatives and similar repositories for JNDI-Exploit-Kit:
Users that are interested in JNDI-Exploit-Kit are comparing it to the libraries listed below
- A malicious LDAP server for JNDI injection attacks☆1,027Updated last year
- Log4Shell scanner for Burp Suite☆483Updated last year
- Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user☆1,011Updated 2 years ago
- CVE-2021-42287/CVE-2021-42278 Scanner & Exploiter.☆1,363Updated 3 years ago
- 🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks☆935Updated 3 years ago
- Java RMI Vulnerability Scanner☆855Updated 9 months ago
- Log4j jndi injects the Payload generator☆485Updated 3 years ago
- WSO2 RCE (CVE-2022-29464) exploit and writeup.☆369Updated 2 years ago
- Sudo Baron Samedit Exploit☆744Updated 3 years ago
- HTTP Protocol Stack Remote Code Execution Vulnerability CVE-2022-21907☆361Updated 3 years ago
- Windows Privilege Escalation from User to Domain Admin.☆1,377Updated 2 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆595Updated 4 years ago
- Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965☆364Updated 2 years ago
- JMX enumeration and attacking tool.☆428Updated 2 weeks ago
- RCE 0-day for GhostScript 9.50 - Payload generator☆545Updated 3 years ago
- Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user☆858Updated 2 years ago
- Burpsuite extension for log4j2rce☆28Updated 3 years ago
- Collection of PoC and offensive techniques used by the BlackArrow Red Team☆1,112Updated 8 months ago
- Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE)☆788Updated 3 years ago
- Exploit for zerologon cve-2020-1472☆653Updated 4 years ago
- Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.☆822Updated 3 years ago
- Exploit allowing you to read registry hives as non-admin on Windows 10 and 11☆743Updated 3 years ago
- Kerberos unconstrained delegation abuse toolkit☆1,271Updated 2 months ago
- Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation☆958Updated 2 years ago
- Ghostcat read file/code execute,CNVD-2020-10487(CVE-2020-1938)☆383Updated 5 years ago
- Log4Shell RCE Exploit - fully independent exploit does not require any 3rd party binaries.☆256Updated 3 years ago
- ☆768Updated 2 years ago
- Hide your payload in DNS☆612Updated last year
- A list of useful Powershell scripts with 100% AV bypass (At the time of publication).☆1,087Updated 2 months ago
- Exploit Code for CVE-2020-1472 aka Zerologon☆382Updated 4 years ago