ripsscanner / rips
RIPS - A static source code analyser for vulnerabilities in PHP scripts
☆352Updated 8 years ago
Alternatives and similar repositories for rips:
Users that are interested in rips are comparing it to the libraries listed below
- Security-related PHP7 OPcache abuse tools and demo☆310Updated 2 years ago
- A tool that can scan php vulnerabilities automatically using static analysis methods☆488Updated 6 years ago
- PHP Runtime Vulnerability Detection☆480Updated 5 years ago
- Php Codz Hacking☆654Updated 9 years ago
- A PHP7 extension that can hook most functions/classes and parts of opcodes☆241Updated 3 years ago
- a simple tool to detect potential security threat in php code☆308Updated 5 months ago
- 分享PHP WebShell 绕过WAF 的一些经验 Share some experience about PHP WebShell bypass WAF and Anti-AV☆294Updated 7 years ago
- small set of PHP scripts to practice exploiting LFI, RFI and CMD injection vulns☆325Updated 10 months ago
- RIPS - A static source code analyser for vulnerabilities in PHP scripts☆312Updated 3 years ago
- Pixy is a scanner static code analysis tools that scans PHP applications for security vulnerabilities.☆140Updated last year
- Taint is a PHP extension, used for detecting XSS codes☆610Updated 8 months ago
- A Control Flow Graph implementation in PHP☆245Updated last month
- Code-Audit-Challenges☆980Updated 6 years ago
- SHELLING - a comprehensive OS command injection payload generator☆444Updated 4 years ago
- Content hijacking proof-of-concept using Flash, PDF and Silverlight☆379Updated 5 years ago
- CMS渗透测试框架-A CMS Exploit Framework☆582Updated 7 years ago
- Add headers to all Burp requests to bypass some WAF products☆330Updated 7 years ago
- webshell sample for WebShell Log Analysis☆417Updated 3 years ago
- J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tes…☆650Updated last year
- [DEPRECATED]A novel SQL injection detection engine built on top of SQL tokenizing and syntax analysis.☆254Updated 11 months ago
- Proof-of-concept to exploit the flaw in the PHP-GD built-in function, imagecreatefromjpeg()☆148Updated 9 years ago
- SQLi-Hunter is a simple HTTP / HTTPS proxy server and a SQLMAP API wrapper that makes digging SQLi easy.☆430Updated 10 months ago
- Simple php backdoor based on extension☆74Updated 10 years ago
- Taint Analysis for PHP☆45Updated 8 years ago
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,190Updated last year
- procfs-based PHP sandbox bypass☆133Updated 6 years ago
- A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.☆514Updated 4 years ago
- Create a TCP circuit through validly formed HTTP requests☆345Updated 7 years ago
- WAF Bypass Cheatsheet☆212Updated 7 years ago
- Your interpreter isn’t safe anymore — The PHP module backdoor☆221Updated 5 years ago