
wordpress-hacking
A collection of useful resources for hacking WordPress and it's plugins and themes

A collection of useful resources for hacking WordPress and it's plugins and themes

GUI Burp Plugin to ease discovering of security holes in web applications


Automatic SSTI detection tool with interactive interface

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

Laravel debug mode - Remote Code Execution (RCE)

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…