
agartha
Burp Suite extension for automated injection flaw detection (LFI, RCE, SQLi), access control assessment via Auth Matrix, HTTP 403 bypass, and dynamic…

Burp Suite extension for automated injection flaw detection (LFI, RCE, SQLi), access control assessment via Auth Matrix, HTTP 403 bypass, and dynamic…

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Automated HTTP Request Repeating With Burp Suite

A curated collection of proof-of-concept exploit scripts for disclosed CVEs, targeting web applications, network devices, and enterprise software for…

Curated cybersecurity learning library with tutorials, mindmaps, vulnerable code snippets, and methodology breakdowns across web pentesting, bug…

A tool to extract the IdP cert from vCenter backups and log in as Administrator

Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Exploit for CVE-2022-23131: Zabbix SAML authentication bypass. Replaces session cookie to gain unauthorized admin access via Single Sign-On.

Remote code execution exploit for Tongda Office Anywhere OA systems via arbitrary file upload and local file inclusion vulnerabilities, with webshell…

CVE-2024-27198 & CVE-2024-27199 Authentication Bypass --> RCE in JetBrains TeamCity Pre-2023.11.4

Exploit script for CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, enabling authentication bypass and remote code execution with user…

Jupyter notebooks and scripts for testing and analyzing OAuth 2.0 grants and OpenID Connect authentication flows, including certificate auth and JWT…

Proof-of-concept exploit for Microsoft SharePoint CVE-2026-55040 that forges JWT tokens, bypasses authentication, auto-discovers metadata, and…

Proof-of-concept demonstrating CVE-2025-29927, a Next.js middleware bypass using the x-middleware-subrequest header to circumvent authentication and…

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens