A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Jul 21, 2020 - Python
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Bypass Paywalls web browser extension for Chrome and Firefox.
Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software protection .
Curated list of Unix binaries that can be exploited to bypass system security restrictions
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
Bypass Paywalls for Firefox
Detect and bypass web application firewalls and protection systems
Undetectable Windows Payload Generation
Penetration tests guide based on OWASP including test cases, resources and examples.
流量转发加速工具.ping tunnel is a tool that advertises tcp/udp/socks5 traffic as icmp traffic for forwarding.
渗透测试有关的POC、EXP、脚本、提权、小工具等,欢迎补充、完善---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures.
Series of System Administration Tools
A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques
A big list of Android Hackerone disclosed reports and other resources.
An Python Script For Generating Payloads that Bypasses All Antivirus so far .
Antivirus evasion project
Handbook of information collection for penetration testing and src
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
bebasid dapat membantu membuka halaman situs web yang diblokir oleh pemerintah Indonesia dengan memanfaatkan hosts file.
Bypassing WAF by abusing SSL/TLS Ciphers
Cloudflare real IP tracker.
Add a description, image, and links to the bypass topic page so that developers can more easily learn about it.
To associate your repository with the bypass topic, visit your repo's landing page and select "manage topics."