Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.
☆121Feb 22, 2026Updated 5 months ago
Alternatives and similar repositories for Research_Successful_Errors
Users that are interested in Research_Successful_Errors are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆238Jul 24, 2025Updated last year
- Finds graphql queries in javascript files☆69May 18, 2024Updated 2 years ago
- GoLang package for creating Mythic Payload Types, C2 Profiles, Translation Services, WebHook listeners, and Loggers☆26Jul 14, 2026Updated 2 weeks ago
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 3 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆105Feb 9, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆92Mar 25, 2024Updated 2 years ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated last year
- Deserialization payload generator for a variety of .NET formatters☆202Updated this week
- A .git/ folder disclosure exploit☆22Jul 14, 2019Updated 7 years ago
- ☆18Oct 30, 2022Updated 3 years ago
- CRLF Detection based on @BlackFan 's work See link below☆17Mar 14, 2024Updated 2 years ago
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆69May 11, 2026Updated 2 months ago
- Rust-powered HTTP Request Smuggling Scanner.☆125Updated this week
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆48Dec 4, 2025Updated 7 months ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆865Updated this week
- ☆11Dec 19, 2024Updated last year
- ☆24Oct 17, 2024Updated last year
- Automatic SSTI detection tool with interactive interface☆1,588Apr 25, 2026Updated 3 months ago
- Abuse trust-boundaries to bypass firewalls and network controls☆424Jul 10, 2026Updated 2 weeks ago
- Content-Type Research☆669Jun 29, 2025Updated last year
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 4 months ago
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 5 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆149Dec 9, 2024Updated last year
- A collection of js analysis tools & scripts.☆19May 4, 2026Updated 2 months ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆982Dec 31, 2021Updated 4 years ago
- web app monitoring automation☆15Jan 7, 2025Updated last year
- A remote live memory viewer PoC based on the MongoBleed vulnerability primitive!☆30Apr 7, 2026Updated 3 months ago
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆809Dec 9, 2025Updated 7 months ago
- Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used …☆255Dec 9, 2025Updated 7 months ago
- ☆51Aug 2, 2025Updated 11 months ago
- Header Exploitation HTTP☆760May 28, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- CT Log Scanner☆568Dec 26, 2025Updated 7 months ago
- Burp plugin for jxscout☆23May 12, 2025Updated last year
- An extension for Burp's Web Vulnerability Scanner that can detect API discovery metadata and extract data useful during recon.☆19Sep 13, 2025Updated 10 months ago
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,822Jun 21, 2026Updated last month
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- New exploitation tricks for hardened .NET Remoting servers☆33Aug 5, 2025Updated 11 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆113Updated this week