shurmajee / postmessage-vulnerability-demo
HTML source files demonstrating HTML5 postmessage vulnerabilities
☆19Updated 4 years ago
Alternatives and similar repositories for postmessage-vulnerability-demo
Users that are interested in postmessage-vulnerability-demo are comparing it to the libraries listed below
Sorting:
- A Burp Extender plugin that will allow you to tamper with requests containing compressed, serialized java objects.☆24Updated 6 years ago
- ☆35Updated 3 months ago
- ☆26Updated 2 years ago
- Accompanying material needed for the workshop☆11Updated last year
- ☆30Updated last year
- HTTP requests of FrontPage expolit☆25Updated 11 years ago
- Checklist for pentests, handy commands for to remembers, and a few tools to work on here and there. Far from complete!☆26Updated last year
- This extension replaces the default repeater tab name with the URL path of the repeater request.☆22Updated 3 years ago
- ☆19Updated 4 years ago
- ☆22Updated 3 years ago
- SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environme…☆47Updated 4 years ago
- A Burp Suite extension for headless, unattended scanning.☆36Updated 4 years ago
- Extract subdomains from rapiddns.io☆23Updated 2 years ago
- ☆1Updated 4 years ago
- A tool to password spray Jenkins instances☆56Updated 5 years ago
- Noob Penetration tester☆11Updated 11 months ago
- Just a simple SMTP server, implementation of @corpix smtpd library☆14Updated 5 years ago
- A Burp extension to show the Collaborator client in a tab☆23Updated 2 years ago
- Automated compromise detection of the world's most popular packages☆15Updated last year
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆76Updated 4 years ago
- Script written in python to perform Resource-Based Constrained Delegation (RBCD) attack by leveraging Impacket toolkit.☆21Updated 3 years ago
- A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.☆14Updated 3 years ago
- Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets☆43Updated 2 years ago
- Modified version of PEAS client for offensive operations☆41Updated 2 years ago
- Tool to extract & validate google fcm server keys from apks☆28Updated 4 years ago
- Scanner for Cross-Site WebSocket Hijacking☆42Updated 4 years ago
- BurpSuite's payload-generation extension aiming at applying fuzzed test-cases depending on the type of payload (integer, string, path; JS…☆41Updated 4 years ago
- A Burp Suite extension to add a custom header (e.g. JWT)☆19Updated 3 years ago
- Perform Windows domain enumeration via LDAP☆36Updated 2 years ago
- Building ActiveDirectory Lab for practicing various attack vectors used during Red Team engagement.☆36Updated 5 years ago