Tanner Barnes's repositories

BurpSuiteAutoCompletion

This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.

Language:JavaStargazers:164Issues:8Issues:0

CloudCopy

This tool implements a cloud version of the Shadow Copy attack against domain controllers running in AWS using only the EC2:CreateSnapshot permission.

ParameterMiner

Built on a lazy Sunday after seeing this tweet (https://twitter.com/intigriti/status/1272145863868104705?s=20) I present to you, ParameterMiner! Pipe in a list of javascript urls and ParameterMiner pulls all the variable names.

goRecorder

During pentesting I often miss screenshots of events for reports due to the quick pace of testing and a lack of foreknowledge about what will be important. To remedy that problem (and also to teach myself go) I built a command line tool that implements the "clip that" functionality of gaming consoles to allow me to save the last minute of screen activity as images to later view.

BurpSuiteAutoRepeaterNaming

This extension replaces the default repeater tab name with the URL path of the repeater request.

BurpRequestCleaner

This extension redacts potentially sensitive header and parameter values from requests using Shannon Entropy analysis.

Language:JavaStargazers:12Issues:4Issues:0

LORC

LORC - Low Orbit RECON Cannon

Language:GoStargazers:12Issues:4Issues:0

aem-rce

Python and Metasploit module for exploiting Adobe Experience Manager (AEM) default credentials which can be used to achieve RCE

Language:PythonStargazers:7Issues:3Issues:0

GoPatternMatcher

This tool allows for quickly searching for a specified pattern within HTTP Response bodies. Simply pipe in a list of URLs, specify your pattern and hit enter.

Language:GoStargazers:5Issues:3Issues:0

ratt

Recon All The Things (R.A.T.T.) provides a quick and easy way to spider a target ( or multiple targets ) and retrieve infomation key to further recon steps such as javascript files, relative/absolute paths referenced on the page, headers used in requests, and more!

Language:GoStargazers:4Issues:2Issues:0

Console

Faction C2 Framework Console Service

Language:VueLicense:BSD-3-ClauseStargazers:1Issues:2Issues:0

EyeWitness

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Language:PythonLicense:GPL-3.0Stargazers:1Issues:2Issues:0

Hibernate-Injection-Study

Study about HQL injection exploitation.

Language:PerlStargazers:1Issues:2Issues:0

XSSContentDiscover

This is a PoC for an attack path I've seen on multiple engagements I wanted to standardize.

Language:PHPStargazers:1Issues:1Issues:0

braindump

BrainDump is a simple, powerful, and open note taking platfform that makes it easy to organize your life.

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

Codiad

Web Based, Cloud IDE

Language:PHPLicense:MITStargazers:0Issues:2Issues:0

DocumentServer

ONLYOFFICE Document Server is an online office suite comprising viewers and editors for texts, spreadsheets and presentations, fully compatible with Office Open XML formats: .docx, .xlsx, .pptx and enabling collaborative editing in real time.

Language:ShellLicense:AGPL-3.0Stargazers:0Issues:2Issues:0

gophish

Open-Source Phishing Toolkit

Language:GoLicense:NOASSERTIONStargazers:0Issues:0Issues:0

govultr

Vultr Go API client

Language:GoLicense:MITStargazers:0Issues:2Issues:0
Language:JavaStargazers:0Issues:2Issues:0

machat

An open source chat server implemented in Go

Language:GoLicense:MITStargazers:0Issues:2Issues:0

screenshot

Go library to capture desktop to image

Language:GoLicense:MITStargazers:0Issues:0Issues:0

townhall-news-extension

This Chrome Extension pulls in the top 5 news stories about all the politicians and government bodies that represent your area. Simply load the chrome extension and navigate to https://www.facebook.com/townhall/?tab=directory.

Language:JavaScriptStargazers:0Issues:2Issues:0