
Tools for testing, exploiting, and securing web applications and APIs.


Sparty - MS Sharepoint and Frontpage Auditing Tool [Unofficial]

Grails sample application using the Javamelody 1.44 plugin to illustrate the CVE-2013-4378 vulnerability.


metasploit module for CVE-2013-3319 / SAP Security Note 1816536

Transparent proxy that decrypts SSL traffic and prints out IRC messages.


ActionScript Proof of Concept to perform cross-domain reads

ActionScript Proof of Concept to perform cross-domain reads

A free and open source command-line shell and scripting language designed especially for security testing


Radamsa fuzzer extension for Burp Suite

Novell ZENworks Mobile Management - LFI RCE


ISR-sqlget It's a blind SQL injection tool developed in Perl.

MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop…

Bootstrapped Rails 3.2.10 to test the remote code exploit CVE-2013-0156