Self contained htaccess shells and attacks
☆1,075Feb 17, 2022Updated 4 years ago
Alternatives and similar repositories for htshells
Users that are interested in htshells are comparing it to the libraries listed below
Sorting:
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,123Apr 21, 2024Updated last year
- The cheat sheet about Java Deserialization vulnerabilities☆3,167May 26, 2023Updated 2 years ago
- A swiss army knife for pentesting networks☆9,082Dec 6, 2023Updated 2 years ago
- A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, al…☆1,285Aug 18, 2025Updated 6 months ago
- SMBMap is a handy SMB enumeration tool☆2,020Jan 6, 2026Updated last month
- Wiki to collect Red Team infrastructure hardening resources☆4,450Oct 1, 2025Updated 5 months ago
- PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.☆3,753Sep 29, 2025Updated 5 months ago
- .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers☆2,916Nov 19, 2025Updated 3 months ago
- ODAT: Oracle Database Attacking Tool☆1,743Jul 27, 2024Updated last year
- Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.☆1,710Dec 1, 2024Updated last year
- A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and…☆3,903Sep 27, 2021Updated 4 years ago
- Miscellaneous exploit code☆1,568Oct 6, 2023Updated 2 years ago
- The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.☆3,152Mar 6, 2025Updated 11 months ago
- PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server☆2,689Dec 12, 2024Updated last year
- Deserialization payload generator for a variety of .NET formatters☆3,679Dec 23, 2024Updated last year
- PowerShell Pass The Hash Utils☆1,724Dec 9, 2018Updated 7 years ago
- Weaponized web shell☆3,486Oct 1, 2025Updated 5 months ago
- Automatic SSRF fuzzer and exploitation tool☆3,489Sep 4, 2025Updated 6 months ago
- HTTP parameter discovery suite.☆6,091Feb 20, 2025Updated last year
- Automated All-in-One OS Command Injection Exploitation Tool☆5,640Feb 22, 2026Updated last week
- A tool to abuse Exchange services☆2,300Jun 10, 2024Updated last year
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,650Jan 5, 2026Updated last month
- Post Exploitation Collection☆1,570May 1, 2020Updated 5 years ago
- latest version of scanners for IIS short filename (8.3) disclosure vulnerability☆1,632Sep 3, 2023Updated 2 years ago
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,302Apr 18, 2023Updated 2 years ago
- A Tool for Domain Flyovers☆5,906May 22, 2022Updated 3 years ago
- This tool can be used to brute discover GET and POST parameters☆1,394Aug 24, 2019Updated 6 years ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,831Nov 10, 2023Updated 2 years ago
- Exploitation for XSS☆731Aug 5, 2021Updated 4 years ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,173May 11, 2023Updated 2 years ago
- Automated NoSQL database enumeration and web application exploitation tool.☆3,238Feb 20, 2026Updated last week
- DotDotPwn - The Directory Traversal Fuzzer☆1,108Sep 28, 2022Updated 3 years ago
- ☆2,316Dec 8, 2023Updated 2 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,765Dec 4, 2025Updated 3 months ago
- SSRF (Server Side Request Forgery) testing resources☆2,482Oct 12, 2024Updated last year
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆9,779Apr 25, 2024Updated last year
- Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's po…☆3,900Jan 24, 2024Updated 2 years ago
- A Ruby framework designed to aid in the penetration testing of WordPress systems.☆1,043Nov 24, 2019Updated 6 years ago
- Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor☆2,448May 6, 2024Updated last year