Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.
☆122Feb 22, 2026Updated 6 months ago
Alternatives and similar repositories for Research_Successful_Errors
Users that are interested in Research_Successful_Errors are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆241Jul 24, 2025Updated last year
- Finds graphql queries in javascript files☆69May 18, 2024Updated 2 years ago
- GoLang package for creating Mythic Payload Types, C2 Profiles, Translation Services, WebHook listeners, and Loggers☆25Jul 30, 2026Updated last month
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 4 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆104Feb 9, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆92Mar 25, 2024Updated 2 years ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- Deserialization payload generator for a variety of .NET formatters☆229Aug 25, 2026Updated last week
- ☆18Oct 30, 2022Updated 3 years ago
- A .git/ folder disclosure exploit☆22Jul 14, 2019Updated 7 years ago
- CRLF Detection based on @BlackFan 's work See link below☆17Mar 14, 2024Updated 2 years ago
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆70May 11, 2026Updated 3 months ago
- Rust-powered HTTP Request Smuggling Scanner.☆130Aug 30, 2026Updated last week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆50Dec 4, 2025Updated 9 months ago
- ☆10Dec 19, 2024Updated last year
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆875Aug 24, 2026Updated last week
- ☆24Oct 17, 2024Updated last year
- Abuse trust-boundaries to bypass firewalls and network controls☆434Jul 10, 2026Updated last month
- Automatic SSTI detection tool with interactive interface☆1,631Aug 25, 2026Updated last week
- Content-Type Research☆670Jun 29, 2025Updated last year
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆150Dec 9, 2024Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 6 months ago
- A collection of js analysis tools & scripts.☆19May 4, 2026Updated 4 months ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆988Dec 31, 2021Updated 4 years ago
- web app monitoring automation☆15Jan 7, 2025Updated last year
- A remote live memory viewer PoC based on the MongoBleed vulnerability primitive!☆31Apr 7, 2026Updated 5 months ago
- Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used …☆256Dec 9, 2025Updated 8 months ago
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆814Dec 9, 2025Updated 8 months ago
- Header Exploitation HTTP☆763Updated this week
- CT Log Scanner☆585Dec 26, 2025Updated 8 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- ☆51Aug 2, 2025Updated last year
- An extension for Burp's Web Vulnerability Scanner that can detect API discovery metadata and extract data useful during recon.☆19Sep 13, 2025Updated 11 months ago
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,873Jun 21, 2026Updated 2 months ago
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- New exploitation tricks for hardened .NET Remoting servers☆33Aug 5, 2025Updated last year
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆127Updated this week