sdcampbell / phpLFILinks
Tests for LFI in PHP apps and automates the process of leveraging LFI's to recursively download source code and discover new files via includes to download additional source code files.
☆13Updated 2 years ago
Alternatives and similar repositories for phpLFI
Users that are interested in phpLFI are comparing it to the libraries listed below
Sorting:
- Modified version of PEAS client for offensive operations☆41Updated 2 years ago
- Perform Windows domain enumeration via LDAP☆36Updated 3 years ago
- Similar to Petitpotam, the netdfs service is enabled in Windows Server and AD environments, and the abused RPC method allows privileged p…☆49Updated 3 years ago
- Right-To-Left Override POC☆35Updated 3 years ago
- c# reverse shell poc☆27Updated 6 years ago
- Execute Mimikatz with different technique☆51Updated 3 years ago
- Convert ldapdomaindump to Bloodhound☆81Updated last year
- A script that greps composite key-like strings from a KeePassXC process dump, then uses a customized version of pykeepass library to unlo…☆32Updated 2 years ago
- Bypass Constrained Language Mode in PowerShell☆30Updated 6 years ago
- ☆18Updated 4 years ago
- A script used to query the dehashed API and filter for more useful results☆17Updated 4 years ago
- Kudzu is a Go C2 platform with an emphasis on extensibility.☆11Updated 4 years ago
- Finding SSL Blindspots for Red Teams☆32Updated 5 years ago
- A cloud automation system for Red Teams based on Terraform and Ansible☆24Updated 4 years ago
- A C# Tool to find left over pentest data for use in your pentest or redteam op. Blue could maybe use to find files to cleanup☆38Updated last year
- Checks for signature requirements over LDAP☆97Updated 2 years ago
- ☆19Updated last year
- User enumeration and password spraying tool for testing Azure AD☆70Updated 3 years ago
- Multi-thread AzureAD Autologon SSO Password Sprayer.☆37Updated 3 years ago
- ☆31Updated 2 years ago
- WptsExtensions.dll for exploiting DLL hijacking of the task scheduler.☆55Updated 4 years ago
- Use rpc null sessions to retrieve machine list, domain admin list, domain controllers☆14Updated 2 years ago
- ☆23Updated 3 years ago
- Azure pentesting reference for Altered Security Lab☆24Updated 3 years ago
- Compiled Binaries for Sharp Suite☆15Updated 5 years ago
- A multithreaded, queued SSH key and/or password spraying tool.☆20Updated 2 years ago
- Multi-threaded C2 framework built in Flask with keylogger - from the Offensive C# Course by Naga Sai Nikhil☆21Updated 2 years ago
- Script written in python to perform Resource-Based Constrained Delegation (RBCD) attack by leveraging Impacket toolkit.☆21Updated 4 years ago
- A little implant which SSH's back with a shell☆38Updated 3 years ago
- Tooling I utilized within the PEN300 training labs☆4Updated 2 years ago