All Projects → swisskyrepo → Payloadsallthethings

swisskyrepo / Payloadsallthethings

Licence: mit
A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Programming Languages

python
139335 projects - #7 most used programming language
ruby
36898 projects - #4 most used programming language
ASP.NET
160 projects
Classic ASP
548 projects
PHP
23972 projects - #3 most used programming language
Jupyter Notebook
11667 projects

Projects that are alternatives of or similar to Payloadsallthethings

Aboutsecurity
A list of payload and bypass lists for penetration testing and red team infrastructure build.
Stars: ✭ 166 (-99.5%)
Mutual labels:  cheatsheet, methodology, hacking, pentest, redteam, payload, bypass
Pentest Guide
Penetration tests guide based on OWASP including test cases, resources and examples.
Stars: ✭ 1,316 (-96%)
Mutual labels:  penetration-testing, pentest, vulnerability, payload, bypass, bugbounty
A Red Teamer Diaries
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
Stars: ✭ 382 (-98.84%)
Mutual labels:  hacking, penetration-testing, vulnerability, redteam, enumeration, privilege-escalation
Active Directory Exploitation Cheat Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Stars: ✭ 1,392 (-95.77%)
Mutual labels:  cheatsheet, hacking, penetration-testing, enumeration, privilege-escalation
Active Directory Exploitation Cheat Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Stars: ✭ 870 (-97.36%)
Mutual labels:  cheatsheet, hacking, penetration-testing, enumeration, privilege-escalation
web-fuzz-wordlists
Common Web Managers Fuzz Wordlists
Stars: ✭ 137 (-99.58%)
Mutual labels:  web-application, penetration-testing, vulnerability, pentest, payloads
Writeups
This repository contains writeups for various CTFs I've participated in (Including Hack The Box).
Stars: ✭ 61 (-99.81%)
Mutual labels:  enumeration, penetration-testing, pentest, payload, privilege-escalation
Nosqlmap
Automated NoSQL database enumeration and web application exploitation tool.
Stars: ✭ 1,928 (-94.14%)
Mutual labels:  hacktoberfest, hacking, penetration-testing, enumeration, bugbounty
Xxe Injection Payload List
🎯 XML External Entity (XXE) Injection Payload List
Stars: ✭ 304 (-99.08%)
Mutual labels:  hacking, payload, payloads, bugbounty
Asnlookup
Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.
Stars: ✭ 163 (-99.5%)
Mutual labels:  hacking, pentest, enumeration, bugbounty
Resources
A Storehouse of resources related to Bug Bounty Hunting collected from different sources. Latest guides, tools, methodology, platforms tips, and tricks curated by us.
Stars: ✭ 62 (-99.81%)
Mutual labels:  methodology, hacking, penetration-testing, bugbounty
Payloads
Git All the Payloads! A collection of web attack payloads.
Stars: ✭ 2,862 (-91.3%)
Mutual labels:  hacking, pentest, payload, payloads
Crithit
Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Stars: ✭ 182 (-99.45%)
Mutual labels:  hacking, penetration-testing, enumeration, bugbounty
Interlace
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
Stars: ✭ 760 (-97.69%)
Mutual labels:  hacking, penetration-testing, enumeration, bugbounty
Oscp Prep
my oscp prep collection
Stars: ✭ 105 (-99.68%)
Mutual labels:  cheatsheet, methodology, hacking, penetration-testing
K8tools
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
Stars: ✭ 4,173 (-87.32%)
Mutual labels:  hacking, pentest, bypass, privilege-escalation
PayloadsAll
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Stars: ✭ 31 (-99.91%)
Mutual labels:  vulnerability, bugbounty, pentest, payloads
Payloads
Payload Arsenal for Pentration Tester and Bug Bounty Hunters
Stars: ✭ 421 (-98.72%)
Mutual labels:  penetration-testing, bugbounty, payload, payloads
Dirsearch
Web path scanner
Stars: ✭ 7,246 (-77.98%)
Mutual labels:  hacking, penetration-testing, enumeration, bugbounty
Sql Injection Payload List
🎯 SQL Injection Payload List
Stars: ✭ 716 (-97.82%)
Mutual labels:  hacking, payload, payloads, bugbounty

Payloads All The Things Tweet

A list of useful payloads and bypasses for Web Application Security. Feel free to improve with your payloads and techniques ! I ❤️ pull requests :)

You can also contribute with a 🍻 IRL, or using the sponsor button.

Every section contains the following files, you can use the _template_vuln folder to create a new chapter:

  • README.md - vulnerability description and how to exploit it, including several payloads
  • Intruder - a set of files to give to Burp Intruder
  • Images - pictures for the README.md
  • Files - some files referenced in the README.md

You might also like the Methodology and Resources folder :

You want more ? Check the Books and Youtube videos selections.

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].