qtc-de / beanshooter
JMX enumeration and attacking tool.
☆422Updated this week
Alternatives and similar repositories for beanshooter:
Users that are interested in beanshooter are comparing it to the libraries listed below
- Java RMI Vulnerability Scanner☆854Updated 8 months ago
- jolokia-exploitation-toolkit☆287Updated 3 months ago
- This tool is for letting you know how strong your disable_functions is and how you can bypass that.☆125Updated 5 years ago
- Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.☆595Updated 4 years ago
- ☆281Updated 3 years ago
- HopLa Burp Suite Extender plugin - Adds autocompletion support and useful payloads in Burp Suite☆725Updated 3 years ago
- ☆406Updated 2 years ago
- IOXIDResolver.py from AirBus Security☆239Updated last year
- That repository contains my updates to the well know java deserialization exploitation tool ysoserial.☆176Updated 2 years ago
- ☆402Updated 3 years ago
- RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities☆428Updated 2 years ago
- Burp Extensions Api☆160Updated last month
- From an account member of the group Backup Operators to Domain Admin without RDP or WinRM on the Domain Controller☆417Updated 2 months ago
- Subdomains analysis and generation tool. Reveal the hidden!☆237Updated 2 weeks ago
- MOGWAI LABS JMX exploitation toolkit☆200Updated 2 years ago
- Proxylogon & Proxyshell & Proxyoracle & Proxytoken & All exchange server history vulns summarization :)☆524Updated last year
- ☆380Updated 3 years ago
- Proof of Concept Exploit for vCenter CVE-2021-21972☆260Updated 4 years ago
- RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.☆351Updated 2 years ago
- Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.☆195Updated 9 months ago
- RCE exploit for CVE-2023-3519☆223Updated last year
- POC for VMWARE CVE-2022-22954☆281Updated 2 years ago
- Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user☆853Updated 2 years ago
- Kraken, a modular multi-language webshell coded by @secu_x11☆538Updated last year
- A tool to embed XXE and XSS payloads in docx, odt, pptx, xlsx files (oxml_xxe on steroids)☆592Updated last year
- Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease appli…☆237Updated 3 months ago
- Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.☆266Updated 2 months ago
- Grafana Unauthorized arbitrary file reading vulnerability☆356Updated 2 years ago
- Black box fuzzer for web applications☆425Updated 8 months ago
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆206Updated 5 months ago