Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.
☆124Feb 22, 2026Updated 7 months ago
Alternatives and similar repositories for Research_Successful_Errors
Users that are interested in Research_Successful_Errors are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆241Jul 24, 2025Updated last year
- Finds graphql queries in javascript files☆69May 18, 2024Updated 2 years ago
- GoLang package for creating Mythic Payload Types, C2 Profiles, Translation Services, WebHook listeners, and Loggers☆25Sep 21, 2026Updated last week
- jxscout superpowers JavaScript analysis for security researchers☆470Apr 12, 2026Updated 5 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆104Feb 9, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Additional resources for leaking and exploiting ObjRefs via HTTP .NET Remoting (CVE-2024-29059)☆92Mar 25, 2024Updated 2 years ago
- Create tar/zip archives that try to exploit zipslip vulnerability.☆48Sep 20, 2024Updated 2 years ago
- Deserialization payload generator for a variety of .NET formatters☆237Updated this week
- ☆18Oct 30, 2022Updated 3 years ago
- A .git/ folder disclosure exploit☆22Jul 14, 2019Updated 7 years ago
- CRLF Detection based on @BlackFan 's work See link below☆17Mar 14, 2024Updated 2 years ago
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆69May 11, 2026Updated 4 months ago
- ☆10Dec 19, 2024Updated last year
- ☆24Oct 17, 2024Updated last year
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Content-Type Research☆671Jun 29, 2025Updated last year
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆152Dec 9, 2024Updated last year
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆876Sep 12, 2026Updated 2 weeks ago
- A collection of js analysis tools & scripts.☆19May 4, 2026Updated 4 months ago
- web app monitoring automation☆15Jan 7, 2025Updated last year
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆992Dec 31, 2021Updated 4 years ago
- Rust-powered HTTP Request Smuggling Scanner.☆133Updated this week
- A remote live memory viewer PoC based on the MongoBleed vulnerability primitive!☆31Apr 7, 2026Updated 5 months ago
- Abuse trust-boundaries to bypass firewalls and network controls☆433Jul 10, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆818Dec 9, 2025Updated 9 months ago
- ☆51Aug 2, 2025Updated last year
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆50Dec 4, 2025Updated 9 months ago
- Header Exploitation HTTP☆764Sep 6, 2026Updated 3 weeks ago
- Stay on the beat with SubHound - receive notifications for new subdomains on Telegram and Discord! 🐶🎵☆17Jun 4, 2023Updated 3 years ago
- Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used …☆257Dec 9, 2025Updated 9 months ago
- CT Log Scanner☆591Dec 26, 2025Updated 9 months ago
- 🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast…☆1,885Jun 21, 2026Updated 3 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆27Jul 15, 2026Updated 2 months ago
- Prototype Pollution and useful Script Gadgets☆1,649Jan 27, 2024Updated 2 years ago
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 6 months ago
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆245Oct 8, 2024Updated last year
- A collection of Server-Side Prototype Pollution gadgets and exploits☆240Feb 6, 2025Updated last year
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 7 months ago
- The Mimikatz Missing Manual☆465Feb 5, 2026Updated 7 months ago