s0md3v / nano
Nano is a family of PHP web shells which are code golfed for stealth.
☆442Updated 5 years ago
Alternatives and similar repositories for nano:
Users that are interested in nano are comparing it to the libraries listed below
- Bypassing disabled exec functions in PHP (c) CRLF☆401Updated 4 years ago
- kadimus is a tool to check and exploit lfi vulnerability.☆531Updated 4 years ago
- JShell - Get a JavaScript shell with XSS.☆521Updated 5 years ago
- Some of my exploits.☆577Updated 4 years ago
- Python3 Burp History parsing tool to discover potential SQL injection points. To be used in tandem with SQLmap.☆468Updated 5 years ago
- Free web-application vulnerability and version scanner☆572Updated last month
- From XSS to RCE 2.75 - Black Hat Europe Arsenal 2017 + Extras☆425Updated 5 years ago
- Exploit written in Python for CVE-2018-15473 with threading and export formats☆522Updated 8 months ago
- This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabi…☆351Updated last month
- Multi Tool Subdomain Enumeration☆726Updated 4 years ago
- Exploitation for XSS☆712Updated 3 years ago
- A tool to find and exploit servers vulnerable to Shellshock☆332Updated last year
- Search for Directory Traversal Vulnerabilities☆436Updated 9 months ago
- Drupal enumeration & exploitation tool☆598Updated 4 years ago
- Extract subdomains from SSL certificates in HTTPS sites.☆384Updated last month
- This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtu…☆634Updated 6 years ago
- SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.☆254Updated 9 months ago
- A friend of SQLmap which will do what you always expected from SQLmap.☆439Updated 5 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆383Updated 4 years ago
- A tool to link a domain with registered organisation names and emails, to other domains.☆841Updated 10 months ago
- Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution☆390Updated 7 years ago
- Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)☆587Updated 4 years ago
- Lesser Known Web Attack Lab☆330Updated 5 years ago
- BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source c…☆546Updated 2 years ago
- A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.☆396Updated 4 years ago
- CMS Detection and Exploit Kit based on Whatcms.org API☆252Updated 4 months ago
- Pentest/BugBounty progress control with scanning modules☆281Updated 4 years ago
- ☆326Updated 7 years ago
- rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments☆245Updated 5 years ago
- Spawn to shell without any credentials by using CVE-2018-10933 (LibSSH)☆498Updated last year