-
ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Java ★ 8.9k 6mo agoExplain → -
jdk8u-jdk ▣
No description.
Java ★ 210 11y agoExplain → -
ciphr
CLI crypto swiss-army knife for performing and composing encoding, decoding, encryption, decryption, hashing, and other various cryptographic operations on streams of data from the command line; mostly intended for ad hoc, infosec-related uses.
Ruby ★ 119 7y agoExplain → -
inspector-gadget
Primitive tool for exploring/querying Java classes via the Tinkerpop Gremlin graph traversal language
Java ★ 108 10y agoExplain → -
grepcidr ▣
from http://www.pc-tools.net/unix/grepcidr/
C ★ 89 9y agoExplain → -
marshalsec ⑂
No description.
Java ★ 76 9y agoExplain → -
jdk8u-dev-jdk ▣
No description.
Java ★ 67 11y agoExplain → -
jdeserialize ▣
From https://code.google.com/p/jdeserialize/
Java ★ 35 11y agoExplain → -
rails_exploits
No description.
Ruby ★ 22 11y agoExplain → -
pd-buddy-wye
From https://git.clarahobbs.com/pd-buddy/pd-buddy-wye.git
★ 11 7y agoExplain → -
serialysis ▣
from http://weblogs.java.net/blog/emcmanus/archive/2007/06/disassembling_s.html
Java ★ 11 11y agoExplain → -
extract-ssl-secrets ⑂
Decrypt HTTPS/SSL/TLS connections on the fly with Wireshark
Java ★ 9 9y agoExplain → -
appseccali-java
No description.
Java ★ 9 11y agoExplain → -
ctfd-trektheme
Star Trek LCARS inspired pure CSS theme for CTFd (v2.1.1) used during the 2019 LayerOne CTF and ToorCon CTF.
CSS ★ 8 5y agoExplain → -
appseccali-marshalling-pickles
Slide deck from AppSecCali 2015 Talk "Marshalling Pickles: how deserializing objects will ruin your day"
CSS ★ 7 10y agoExplain → -
bocker ⑂
Docker implemented in around 100 lines of bash
Shell ★ 7 7y agoExplain → -
sleepyhead ▣
imported from https://sourceforge.net/projects/sleepyhead/
C++ ★ 7 10y agoExplain → -
inyourface ▣
From http://www.synacktiv.com/ressources/inyourface-0.2.tar.gz
Java ★ 7 11y agoExplain → -
owaspsd-deserialize-my-shorts
Slide deck from OWASP SD Talk "Deserialize My Shorts: Or How I Learned to Start Worrying and Hate Java Object Deserialization"
CSS ★ 6 10y agoExplain → -
grepcidr2 ▣
from http://www.taugh.com/grepcidr-2/
C ★ 5 10y agoExplain → -
Java-Deserialization-Cheat-Sheet ⑂
The cheat sheet about Java Deserialization vulnerabilities
★ 5 10y agoExplain → -
jimmix ▣
From http://www.synacktiv.com/ressources/jimmix-0.3.tar.gz
Java ★ 4 11y agoExplain → -
revsh ⑂
A remote access tool for pentesters designed for advanced pivoting.
C ★ 4 9y agoExplain → -
burp-plugin-requestutils
Plugin for manipulating requests in PortSwigger Burp Suite Pro v1.5+
Java ★ 4 13y agoExplain → -
CTFd ⑂
CTFs as you need them
Python ★ 3 5y agoExplain → -
jdk7u ▣
No description.
Java ★ 3 10y agoExplain → -
security_monkey ⑂
Security Monkey
Python ★ 3 8y agoExplain → -
jdk6 ▣
No description.
Java ★ 2 10y agoExplain → -
jmitm2 ▣
From http://www.david-guembel.de/uploads/media/jmitm2-0.1.0-source.tar.gz
Java ★ 2 11y agoExplain → -
shellshock-pocs
No description.
Perl ★ 2 11y agoExplain → -
multiplexd ⑂
run ssh, https, and openvpn on the same port
Go ★ 2 12y agoExplain → -
reverse-proxy-auth-plugin ⑂
No description.
Java ★ 2 12y agoExplain → -
pacemaker ⑂
Heartbleed (CVE-2014-0160) client exploit
Python ★ 2 12y agoExplain → -
rest-client ⑂
Simple HTTP and REST client for Ruby, inspired by microframework syntax for specifying actions.
Ruby ★ 2 12y agoExplain → -
gitlabhq ⑂
Project management and code hosting application. Follow us on twitter @gitlabhq
Ruby ★ 2 13y agoExplain → -
jsdetox ⑂
A Javascript malware analysis tool
★ 2 12y agoExplain → -
self-compile-Android ⑂
Autonomous smartphone app. Capable of self-compilation, mutation, and viral spreading. World-first proof-of-principle to bypass Internet kill switches.
C ★ 2 10y agoExplain → -
pupy ⑂
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python
Python ★ 2 9y agoExplain → -
Empire ⑂
Empire is a PowerShell and Python post-exploitation agent.
PowerShell ★ 2 8y agoExplain → -
d3-profile-viewer ⑂
No description.
Java ★ 2 9y agoExplain → -
Top10 ⑂
Official OWASP Top 10 Document Repository
HTML ★ 2 8y agoExplain → -
wslop
A drop-in replacement for the 1Password CLI's op in WSL (Windows Subsystem for Linux), backed by the analogous Windows op.exe and the 1Password desktop app — no separate Linux sign-in required. Inspired by oprun.sh.
Python ★ 1 1mo agoExplain → -
Hurl ⑂
Choose the browser on the click of a link
C# ★ 1 1y agoExplain → -
java-suid-exec
Break glass in case of suid java executable.
Java ★ 1 11y agoExplain → -
privilegedaccessor ▣
From https://code.google.com/p/privilegedaccessor/
Java ★ 1 11y agoExplain → -
pwdagent
A barebones CLI utility to prompt for and cache a password in memory, then hand it out over HTTP or raw TCP
Ruby ★ 1 11y agoExplain → -
sparring ⑂
Network simulation for malware analysis.
Python ★ 1 12y agoExplain → -
JMD ⑂
Java bytecode analysis/deobfuscation tool
★ 1 14y agoExplain → -
stripe-ctf-2.0 ⑂
Capture the Flag: Web Edition https://stripe.com/blog/capture-the-flag-20
★ 1 13y agoExplain → -
serialization ⑂
Extender module for BurpSuite to decode and re-encode JAVA Object Serialization for security testing
★ 1 13y agoExplain → -
libbf ⑂
Library for binary file manipulation
C ★ 1 13y agoExplain → -
CTF-Scoreboard ⑂
A scoreboard for Security CTF events
JavaScript ★ 1 13y agoExplain → -
git ⑂
Git Source Code Mirror - This is a publish-only repository and all pull requests are ignored. Please follow Documentation/SubmittingPatches procedure for any of your improvements.
C ★ 1 13y agoExplain → -
dotfiles
No description.
Shell ★ 1 13y agoExplain → -
burp-debug
No description.
Java ★ 1 13y agoExplain → -
JavaPayload ⑂
JavaPayload is a collection of pure Java payloads to be used for post-exploitation from pure Java exploits or from common misconfigurations (like not password protected Tomcat manager or debugger port).
Java ★ 1 12y agoExplain → -
sqlmap ⑂
Automatic SQL injection and database takeover tool
Python ★ 1 12y agoExplain → -
frohoff.github.io
Github Pages Site
CSS ★ 1 10y agoExplain → -
metasploit-framework ⑂
Metasploit Framework
Ruby ★ 1 9y agoExplain → -
ghidra ⑂
Ghidra is a software reverse engineering (SRE) framework
★ 1 7y agoExplain → -
lambda-zip-test
docker run -v [homedir]/.aws/:/root/.aws/ -e AWS_DEFAULT_PROFILE=[profilename] [containerid]
Shell ★ 1 9y agoExplain → -
DHCPShock ⑂
Spoofs a DHCP server and exploits all clients vulnerable to the 'ShellShock' bug
★ 1 11y agoExplain → -
javassist ⑂
Java bytecode engineering toolkit
Java ★ 1 11y agoExplain → -
cloudwatch-logs-subscription-consumer ⑂
A specialized Amazon Kinesis stream reader (based on the Amazon Kinesis Connector Library) that can help you deliver data from Amazon CloudWatch Logs to any other system in near real-time using a CloudWatch Logs Subscription Filter.
Java ★ 1 10y agoExplain → -
pwnableweb-scoreboard ⑂
Scoreboard for CTF Competitions
JavaScript ★ 1 10y agoExplain → -
javascript-playlist-parser ⑂
Parse m3u, pls, and asx in JavaScript
CoffeeScript ★ 1 11y agoExplain → -
snarkov ⑂
Sinatra-based Markov bot for Slack.
Ruby ★ 1 11y agoExplain → -
pyvmomi-community-samples ⑂
A place for community contributed samples for the pyVmomi library.
Python ★ 1 10y agoExplain → -
appseccali-rails-redis
No description.
Ruby ★ 1 11y agoExplain → -
reserializer
No description.
Java ★ 1 11y agoExplain → -
ircbots
No description.
Scala ★ 1 16y agoExplain → -
keyring_wincred ⑂
Windows Credential Manager (wincred) backend for python's keyring for WSL
Python ★ 0 15d agoExplain → -
oprun.sh ⑂
The 1-Password CLI's `op run` utility rewritten with `op inject` to add Windows Subsystem for Linux support.
Shell ★ 0 4mo agoExplain → -
sleephq-client
Python client library for sleephq.com OpenAPI API
Python ★ 0 5mo agoExplain → -
tfatool ⑂
Tools for managing files with the Toshiba FlashAir wireless SD card
Python ★ 0 5mo agoExplain → -
docker-ubuntu2404-systemd ⑂
A minimal systemd enabled Ubuntu 24.04 image
Dockerfile ★ 0 5mo agoExplain → -
reloaderoo ⑂
Powerful MCP debugging proxy and CLI inspection tool.
TypeScript ★ 0 5mo agoExplain → -
fido2-ctap-gadget
imported from jejb/fido2-ctap-gadget
C ★ 0 7mo agoExplain → -
netlog-extension ⑂
Monitor network requests and console logs without opening DevTools
★ 0 1y agoExplain → -
microsoft-authentication-library-common-for-android ⑂
Common code used by both the Active Directory Authentication Library (ADAL) and the Microsoft Authentication Library (MSAL)
★ 0 1y agoExplain → -
openssl_tpm2_engine
Cloned from https://git.kernel.org/pub/scm/linux/kernel/git/jejb/openssl_tpm2_engine.git/
C ★ 0 1y agoExplain → -
ysoserial-m2-repo
Makeshift maven2 repo for artifacts missing from other public repos based on https://gist.github.com/cleberjamaral/6c9b0a615e51e26c94ffe407a641f531
★ 0 2y agoExplain → -
jdk8u ▣
No description.
Shell ★ 0 11y agoExplain → -
httpbin ⑂
HTTP Request & Response Service, written in Python + Flask.
★ 0 3y agoExplain → -
htransformation ⑂
A Traefik plugin to change on the fly header's value of a request
Go ★ 0 4y agoExplain → -
test
No description.
★ 0 6y agoExplain → -
commons-collections ⑂
Mirror of Apache Commons Collections
Java ★ 0 10y agoExplain → -
mintapi ⑂
a screen-scraping API for Mint.com
Python ★ 0 8y agoExplain → -
amazon-kinesis-connectors ⑂
No description.
Java ★ 0 10y agoExplain → -
exercism
exercism solutions
Rust ★ 0 5y agoExplain → -
jinja2_markdown ⑂
A jinja2 extension that adds a {% markdown %} tag to jinja.
★ 0 6y agoExplain → -
CTFd-Dark-Theme ⑂
No description.
HTML ★ 0 7y agoExplain → -
courier ⑂
send electronic mail with scala
Scala ★ 0 12y agoExplain → -
yappi
Imported from https://bitbucket.org/sumerc/yappi
Python ★ 0 8y agoExplain → -
hubot-hipchat-api ⑂
A Hubot adapter for HipChat that uses the HipChat API
JavaScript ★ 0 8y agoExplain → -
background-check ⑂
Automatically switch to a darker or a lighter version of an element depending on the brightness of images behind it.
JavaScript ★ 0 9y agoExplain → -
speech-synthesis ⑂
Speech Synthesis polyfill
JavaScript ★ 0 12y agoExplain → -
docker-oracle-jdk ⑂
Docker image which contains oracle jdk (7 and 8)
Makefile ★ 0 9y agoExplain → -
travistest
No description.
★ 0 8y agoExplain → -
phpggc ⑂
No description.
PHP ★ 0 9y agoExplain → -
emailgrades
No description.
JavaScript ★ 0 9y agoExplain → -
iptrap ⑂
A simple, but damn fast sinkhole
Rust ★ 0 9y agoExplain → -
sinkholeupdate ⑂
Using RPZ this script helps to add and remove entries into a Bind DNS Server
Python ★ 0 9y agoExplain → -
final-countdown
No description.
JavaScript ★ 0 8y agoExplain → -
ctfscoreboard ⑂
Scoreboard for Capture The Flag competitions, used by the Google CTF event
Python ★ 0 9y agoExplain → -
docker-apache
No description.
★ 0 10y agoExplain → -
docker-compose-ui ⑂
web interface for Docker Compose
JavaScript ★ 0 10y agoExplain → -
SmartThingsPublic ⑂
No description.
Groovy ★ 0 10y agoExplain → -
dockerstats ⑂
Easy scraping for the Docker stats api.
Go ★ 0 10y agoExplain → -
turbolinks ⑂
Turbolinks makes following links in your web application faster (use with Rails Asset Pipeline)
CoffeeScript ★ 0 11y agoExplain → -
commons-beanutils ⑂
Mirror of Apache Commons Beanutils
Java ★ 0 10y agoExplain → -
exserial ⑂
Java Untrusted Deserialization Exploits Tools
Python ★ 0 10y agoExplain → -
jOOR ⑂
jOOR - Fluent Reflection in Java jOOR is a very simple fluent API that gives access to your Java Class structures in a more intuitive way. The JDK's reflection APIs are hard and verbose to use. Other languages have much simpler constructs to access type meta information at runtime. Let us make Java reflection better.
Java ★ 0 10y agoExplain → -
JavaUnserializeExploits ⑂
No description.
Python ★ 0 10y agoExplain → -
chris.frohoff.org
No description.
CSS ★ 0 10y agoExplain → -
frohoff.org
No description.
★ 0 10y agoExplain → -
ctf-scoreboard-1 ⑂
Repository for the MITRE Capture the Flag scoreboard.
Ruby ★ 0 10y agoExplain → -
ficus ⑂
Scala-friendly companion to Typesafe config
Scala ★ 0 11y agoExplain → -
sentries ⑂
Sentries - For easy fault handling in Scala programs
Scala ★ 0 11y agoExplain → -
splunk-sdk-java ⑂
Splunk Software Development Kit for Java
Java ★ 0 11y agoExplain → -
rails ⑂
Ruby on Rails
Ruby ★ 0 13y agoExplain → -
railspwn
No description.
Ruby ★ 0 11y agoExplain → -
BytecodeParser ⑂
A Java library to parse JVM bytecode, simulate the stack and extract as much information as possible
Java ★ 0 12y agoExplain → -
pykek ⑂
Kerberos Exploitation Kit
Python ★ 0 11y agoExplain → -
nepenthes ⑂
A tool for netpens.
★ 0 11y agoExplain → -
fast-serialization ⑂
FST: fast java serialization drop in-replacement http://ruedigermoeller.github.io/fast-serialization/
★ 0 11y agoExplain → -
pivot-php-app
No description.
PHP ★ 0 12y agoExplain → -
spray-template ⑂
SBT template project for quickly getting started with spray-server
Scala ★ 0 12y agoExplain → -
jquery.tocify.js ⑂
A jQuery Table of Contents plugin that can be themed with Twitter Bootstrap or jQueryUI.
JavaScript ★ 0 12y agoExplain →
No repos match these filters.