
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF


Android Remote Administration Tool

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Automatic SSTI detection tool with interactive interface

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

application server attack toolkit

Python script to inject existing Android applications with a Meterpreter payload.

Injects PHP payloads into JPEG images for web application exploitation, bypassing GD library image processing to achieve remote code execution.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Spring4Shell Proof Of Concept/And vulnerable application CVE-2022-22965

WePWNise generates architecture independent VBA code to be used in Office documents or templates and automates bypassing application control and…

A webshell framework for penetration testers.

C# console application for post-exploitation and red team operations, integrating SharpSploit to execute Mimikatz commands, perform Kerberoasting,…

A Web Vulnerability Scanner and Patcher

Exploiting CVE-2021-44228 in Unifi Network Application for remote code execution and more.

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.