
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Android Remote Administration Tool

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Automatic SSTI detection tool with interactive interface

Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).

Python script to inject existing Android applications with a Meterpreter payload.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

A Web Vulnerability Scanner and Patcher

POC for CVE-2022-47966 affecting multiple ManageEngine products

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

A PoC Java Stager which can download, compile, and execute a Java file in memory.

Example Vulnerable .NET HTTP Remoting

NebulaPulsar is a proof-of-concept in-memory implant framework for Java (JSP) and ASP.NET (ASPX/ASHX/ASMX) webshells, originally developed as part of…

Exploit a vulnerable Spring application with the Spring4Shell (CVE-2022-22965) Vulnerability.

a CLI for ephemeral penetration testing

This project demonstrates a proof-of-concept exploit for CVE-2022-30190, also known as "Follina"—a critical remote code execution vulnerability…