Kali Linux

WebView2-Cookie-Stealer : Attacking With WebView2 Applications

WebView2-Cookie-Stealer, According to Microsoft, “Microsoft Edge WebView2 control allows you to embed web technologies (HTML, CSS, and JavaScript) in your…

2 years ago

Tofu : Windows Offline Filesystem Hacking Tool For Linux

Tofu is a modular tool for hacking offline Windows filesystems and bypassing login screens. Can do hashdumps, OSK-Backdoors, user enumeration…

2 years ago

Frostbyte : FrostByte Is A POC Project That Combines Different Defense Evasion Techniques

FrostByte Is A POC Project That Combines Different Defense Evasion Techniques. In the past few days I've been experimenting with…

2 years ago

Admin-Panel_Finder : A Burp Suite Extension That Enumerates Infrastructure And Application Admin Interfaces

Admin-Panel_Finder is a burp suite extension that enumerates infrastructure and application Admin Interfaces.OWASP References: Classification: Web Application Security Testing >…

2 years ago

Gshell : A Flexible And Scalable Cross-Plaform Shell Generator Tool

Gshell is a simple yet flexible cross-platform shell generator tool. A cross-platform shell generator tool that lets you generate whichever…

2 years ago

DOMDig : DOM XSS Scanner For Single Page Applications

DOMDig is a DOM XSS scanner that runs inside the Chromium web browser and it can scan single page applications…

2 years ago

ConfluencePot : Simple Honeypot For Atlassian Confluence (CVE-2022-26134)

ConfluencePot is a simple honeypot for the Atlassian Confluence unauthenticated and remote OGNL injection vulnerability (CVE-2022-26134). About the vulnerability You…

2 years ago

SharpEventPersist : Persistence By Writing/Reading Shellcode From Event Log

SharpEventPersist is a Persistence by writing/reading shellcode from Event Log. Usage The SharpEventPersist tool takes 4 case-sensitive parameters: -file "C:\path\to\shellcode.bin"-instanceid…

2 years ago

MITM_Intercept : A Little Bit Less Hackish Way To Intercept And Modify non-HTTP Protocols Through Burp And Others

MITM_Intercept is a little bit less hackish way to intercept and modify non-HTTP protocols through Burp and others with SSL…

2 years ago

Jeeves : Time-Based Blind SQLInjection Finder

Jeeves is made for looking to Time-Based Blind SQLInjection through recon. Installation & Requirements Installing Jeeves  $ go install github.com/ferreiraklet/Jeeves@latest…

2 years ago