pimps's repositories

JNDI-Exploit-Kit

JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps vulnerable to JNDI Injection)

Language:JavaLicense:MITStargazers:879Issues:19Issues:0

wsuxploit

This is a weaponized WSUS exploit

ysoserial-modified

That repository contains my updates to the well know java deserialization exploitation tool ysoserial.

Language:JavaLicense:MITStargazers:172Issues:5Issues:0

CVE-2018-7600

Exploit for Drupal 7 <= 7.57 CVE-2018-7600

CVE-2017-5645

CVE-2017-5645 - Apache Log4j RCE due Insecure Deserialization

CVE-2017-1000486

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

Language:PythonLicense:GPL-3.0Stargazers:84Issues:2Issues:1

CVE-2019-2725

WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit

Language:PythonStargazers:48Issues:6Issues:0

gopher-tomcat-deployer

Gopher Tomcat Deployer

Language:PythonLicense:MITStargazers:45Issues:1Issues:0

pdf-NTLMLeaker

This script implements the Proof of Concept attack from the Checkpoint research "NTLM Credentials Theft via PDF Files"

Language:PythonStargazers:22Issues:2Issues:0

docker-java-xxe

Docker image to test XXE attacks in java with tomcat.

Language:SmartyStargazers:5Issues:1Issues:0

rizzoma-docker

This is a docker image to run rizzoma standalone for testing or quick deploys.

Language:CoffeeScriptLicense:GPL-3.0Stargazers:4Issues:1Issues:1

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Language:PythonStargazers:3Issues:2Issues:0

CTF-Write-ups

My CTF Write-ups

CVE-2019-2726

CVE-2019-2725 命令回显

Language:PythonStargazers:1Issues:0Issues:0
Language:YARAStargazers:1Issues:0Issues:0
Language:DockerfileStargazers:0Issues:0Issues:0

donut

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

Language:CLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

ipwndfu

open-source jailbreaking tool for many iOS devices

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

knary

A simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams/Lark/Telegram & Pushover support

Language:GoLicense:GPL-3.0Stargazers:0Issues:0Issues:0

TheGoonies-Assets-1

All the assets done for TheGoonies CTF Team.

License:LGPL-3.0Stargazers:0Issues:1Issues:0

tnumb3rs

CTF Challenge TNumb3rs

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0
Language:JavaScriptStargazers:0Issues:1Issues:0