ropnop / xxetimes
An interactive OOB XXE data exfiltration tool
☆90Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for xxetimes
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆135Updated 3 years ago
- Burp Suite plugin created for using Collaborator tool during manual testing in a comfortable way!☆103Updated 6 years ago
- ☆41Updated 4 years ago
- Fuzzing for LFI using Burpsuite☆59Updated 8 years ago
- XSS Hunter Burp Plugin☆149Updated 6 years ago
- A CRLF ( Carriage Return Line Feed ) Injection attack occurs when a user manages to submit a CRLF into an application. This is most commo…☆46Updated 2 years ago
- siberas JMX exploitation toolkit☆128Updated last year
- Java serialization brute force attack tool.☆124Updated 7 years ago
- A tool that can take a URL or list of URL and prints back SAML consume URL.☆35Updated 5 years ago
- Extension adds a new tab in Burp Suite called Extractor☆42Updated 5 years ago
- Burp Suite Importer - Connect to multiple web servers while populating the sitemap.☆48Updated 4 years ago
- Burp Suite Extensions☆126Updated 11 years ago
- Python script to exploit java unserialize on t3 (Weblogic)☆61Updated 7 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆45Updated 11 years ago
- ☆70Updated 7 years ago
- Some scripts and exploits☆142Updated 6 years ago
- A Burp Extension designed to identify argument injection vulnerabilities.☆118Updated 5 years ago
- An Out-of-Band XXE server for retrieving file contents over FTP.☆174Updated 4 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆52Updated 11 years ago
- CVE-2018-7600 Drupal RCE☆115Updated 6 years ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆98Updated 5 years ago
- Local File Inclusion Exploitation Tool (mirror)☆122Updated 7 years ago
- CVE-2018-7600 - Drupal 7.x RCE☆71Updated 6 years ago
- Burp Suite Attack Selector Plugin☆62Updated 7 years ago
- A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.☆97Updated 6 years ago
- Pillage a git repo found in an accessible web root☆60Updated 13 years ago
- Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)☆125Updated 2 years ago
- DupeKeyInjector☆134Updated 2 years ago
- A collection of scripts to extend Burp Suite☆139Updated 5 years ago
- Full TTY reverse shell over SSH☆57Updated 4 years ago