• Earn real money by being active: Hello Guest, earn real money by simply being active on the forum — post quality content, get reactions, and help the community. Once you reach the minimum credit amount, you’ll be able to withdraw your balance directly. Learn how it works.

blind

  1. itsMe

    Bropper: automatic Blind ROP exploitation tool

    An automatic Blind ROP exploitation python tool Abstract BROP (Blind ROP) was a technique found by Andrew Bittau from Stanford in 2014.     Original paper     Slides Most servers like nginx, Apache, MySQL, and forks then communicate with the client. This means canary and addresses stay the...
  2. itsMe

    SQLbit: automatize boolean-based blind SQL injections

    SQL Blind Injection Tool A script for automatizing boolean-based blind SQL injections. Works with SQLite at least supports using cookies. It uses bitwise comparisons with multithreading to find cell values instead of binary search, which is more efficient. It’s able to:     Search cell values...
  3. itsMe

    identYwaf v1.0.133 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  4. itsMe

    identYwaf v1.0.132 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  5. itsMe

    JSshell v2.9 - JavaScript reverse shell for exploiting XSS remotely or finding blind XSS

    JSshell – a JavaScript reverse shell. This using to exploit XSS remotely, help to find blind XSS, … This tool works for both Unix and Windows operating system and it can be running with both Python 2 and Python 3. This is a big update of JShell – a tool to get a JavaScript shell with XSS by...
  6. itsMe

    identYwaf v1.0.129 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  7. itsMe

    ezXSS v3.6 - test Blind Cross Site Scripting

    ezXSS is an easy way to test (blind) Cross-Site Scripting. Current features     Easy to use dashboard with statics, payloads, view/share/search reports and more     Payload generator     Instant email alert on the payload     Custom javascript for extra testing     Prevent double payloads from...
  8. itsMe

    xcat v1.0.5 - exploit and investigate blind XPath injection

    XCat is a command line tool to exploit and investigate blind XPath injection vulnerabilities. For a complete reference read the documentation here: https://xcat.readthedocs.io/en/latest/ It supports an large number of features:     Auto-selects injections (run xcat injections for a list)    ...
  9. itsMe

    xcat v1.0.4 - exploit and investigate blind XPath injection vulnerabilities

    XCat XCat is a command-line tool to exploit and investigate blind XPath injection vulnerabilities. It supports a large number of features:     Auto-selects injections (run xcat injections for a list)     Detects the version and capabilities of the xpath parser and selects the fastest method...
  10. itsMe

    identYwaf v1.0.127 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  11. itsMe

    Andor - Blind SQL Injection Tool With Golang

    Hidden content
  12. itsMe

    identYwaf v1.0.124 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  13. itsMe

    identYwaf v1.0.123 - Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  14. itsMe

    identYwaf v1.0.120 Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
  15. itsMe

    identYwaf v1.0.118 Blind WAF identification tool

    identYwaf is an identification tool that can recognize web protection type (i.e. WAF) based on blind inference. The blind inference is being done by inspecting responses provoked by a set of predefined offensive (non-destructive) payloads, where those are used only to trigger the web protection...
Back
Top