unix-ninja / shellfire
An exploitation shell focusing on exploiting command injection vulnerabilities, eg., LFI, RFI, SSTI, etc.
☆167Updated 9 months ago
Related projects ⓘ
Alternatives and complementary repositories for shellfire
- Local File Inclusion Exploitation Tool (mirror)☆122Updated 7 years ago
- Check for valid credentials across a network over SMB☆256Updated 10 months ago
- A DB of known Web Application Admin URLS, Username/Password Combos and Exploits☆153Updated 9 years ago
- A unique automated LFi Exploiter with Bind/Reverse Shells☆267Updated 9 years ago
- Github for the scripts utilised during Penetration test☆235Updated 7 years ago
- FruityC2 is a post-exploitation (and open source) framework based on the deployment of agents on compromised machines. Agents are managed…☆205Updated 6 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆383Updated 4 years ago
- A tool to find and exploit servers vulnerable to Shellshock☆333Updated last year
- Penetration testing scripts☆143Updated 6 years ago
- Shodan HQ nmap plugin - passively scan targets☆152Updated 8 years ago
- locate and attack Lync/Skype for Business☆334Updated last month
- Scripts, tools, and proof-of-concepts to aid in a penetration test.☆94Updated 4 years ago
- Meterpreter Paranoid Mode - SSL/TLS connections☆283Updated 5 years ago
- ☆235Updated 5 years ago
- XSSYA (Cross Site Scripting Scanner & Vulnerability Confirmation)☆94Updated last year
- psychoPATH - an advanced path traversal tool. Features: evasive techniques, dynamic web root list generation, output encoding, site map-s…☆270Updated 3 years ago
- A Metasploit auto auxiliary script☆103Updated 2 years ago
- A ton of helpful tools☆335Updated 3 years ago
- udp-proto-scanner is a Perl script which discovers UDP services by sending triggers to a list of hosts☆96Updated 5 months ago
- SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.☆253Updated 5 months ago
- Modified dropbear server which acts as a client and allows authless login☆126Updated 6 years ago
- Snarf man-in-the-middle / relay suite☆202Updated 8 years ago
- Automated Responder/secretsdump.py cracking☆181Updated 8 years ago
- Egressbuster is a method to check egress filtering and identify if ports are allowed. If they are, you can automatically spawn a shell.☆345Updated 3 months ago
- Rid_enum is a null session RID cycle attack for brute forcing domain controllers.☆234Updated 3 months ago
- Notes/Tools for pentesting☆83Updated 11 months ago
- Meterpreter Scripts that I'm working on☆172Updated 5 years ago
- Frontpage and Sharepoint fingerprinting and attack tool.☆277Updated 3 years ago
- Based on URL and Organization Name, collect the IP Ranges, subdomains using various tools like Amass, subfinder, etc.. And check for upho…☆154Updated 6 months ago