awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

16 مستودعات

Awesome GitHub RepositoriesInjection Payloads

Collections of crafted strings designed to test for injection vulnerabilities across various database and execution contexts.

Explore 16 awesome GitHub repositories matching security & cryptography · Injection Payloads. Refine with filters or upvote what's useful.

Awesome Injection Payloads GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • swisskyrepo/payloadsallthethingsالصورة الرمزية لـ swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434عرض على GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Supplies a diverse library of payloads tailored for testing vulnerabilities where applications improperly process remote file inclusions.

    Pythonbountybugbountybypass
    عرض على GitHub↗78,434
  • danielmiessler/seclistsالصورة الرمزية لـ danielmiessler

    danielmiessler/SecLists

    71,596عرض على GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    Provides extensive collections of injection payloads for testing application resilience against unexpected data.

    PHP
    عرض على GitHub↗71,596
  • matrixtm/mhddosالصورة الرمزية لـ MatrixTM

    MatrixTM/MHDDoS

    16,224عرض على GitHub↗

    MHDDoS is a command-line utility designed for volumetric stress testing and infrastructure resilience assessment. It functions as a comprehensive framework for simulating high-volume network and application layer traffic to evaluate the capacity and stability of web services and network infrastructure. The tool distinguishes itself through its ability to generate complex, protocol-specific traffic patterns and raw packet structures. By employing dynamic header randomization and specialized payload injection, it simulates diverse request behaviors intended to test the effectiveness of security

    Generates specialized traffic sequences tailored to exploit the unique processing requirements of different network and application layer protocols.

    Pythonamazon-bypassattackauto-proxy
    عرض على GitHub↗16,224
  • s0md3v/xsstrikeالصورة الرمزية لـ s0md3v

    s0md3v/XSStrike

    14,752عرض على GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Uses pattern matching to identify how user input is reflected in the response and determine the context of potential injection points.

    Pythonwaf-detectionxssxss-bruteforce
    عرض على GitHub↗14,752
  • threat9/routersploitالصورة الرمزية لـ threat9

    threat9/routersploit

    13,150عرض على GitHub↗

    Routersploit is a penetration testing framework designed for the security assessment of embedded network devices and routers. It functions as a comprehensive tool for auditing hardware configurations and testing network protocols to identify and verify security vulnerabilities. The framework utilizes a modular plugin architecture that allows for the dynamic loading of exploit and scanner modules. It provides a centralized command interface that manages target state and executes controlled payloads, enabling the automation of security testing across diverse network hardware. The platform cove

    Crafts and transmits protocol-specific network packets to interact with device services and verify security flaws.

    Pythonbruteforcecredsdictionary-attack
    عرض على GitHub↗13,150
  • screetsec/thefatratالصورة الرمزية لـ screetsec

    screetsec/TheFatRat

    11,038عرض على GitHub↗

    TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a

    Embeds malicious code into legitimate software packages and binaries to test system resilience.

    Caccessibilityantivirusautorun
    عرض على GitHub↗11,038
  • fuzzdb-project/fuzzdbالصورة الرمزية لـ fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819عرض على GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Provides specific payloads to test for remote file inclusion vulnerabilities.

    PHP
    عرض على GitHub↗8,819
  • thekingofduck/fuzzdictsالصورة الرمزية لـ TheKingOfDuck

    TheKingOfDuck/fuzzDicts

    8,355عرض على GitHub↗

    fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i

    Supplies crafted strings used to test for injection vulnerabilities across various execution contexts.

    Pythondirectoryfuzz-testingfuzzer
    عرض على GitHub↗8,355
  • hfiref0x/uacmeالصورة الرمزية لـ hfiref0x

    hfiref0x/UACME

    7,375عرض على GitHub↗

    UACME is a set of specialized tools designed to audit security configurations, escalate user privileges, and circumvent access control restrictions on Windows systems. It functions as a utility for executing commands with elevated privileges by bypassing User Account Control restrictions. The project includes a configuration auditor used to extract and analyze system settings to identify security misconfigurations and vulnerabilities. It provides a collection of techniques for gaining administrative rights on a host. The toolset covers a wide range of privilege escalation and security auditi

    Injects shellcode or binaries into legitimate system processes to evade security monitoring.

    Cbypass-uaccdll-hijack
    عرض على GitHub↗7,375
  • daffainfo/allaboutbugbountyالصورة الرمزية لـ daffainfo

    daffainfo/AllAboutBugBounty

    6,644عرض على GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Provides techniques for exploiting NoSQL operator injection to bypass authentication and extract data.

    bugbugbountybugbountytips
    عرض على GitHub↗6,644
  • landgrey/springbootvulexploitالصورة الرمزية لـ LandGrey

    LandGrey/SpringBootVulExploit

    6,136عرض على GitHub↗

    SpringBootVulExploit عبارة عن مجموعة من أدوات الفحص والتدقيق المصممة لتحديد الثغرات الأمنية، وتسريبات المعلومات، وناقلات التنفيذ داخل أطر عمل تطبيقات Java، وتحديداً التي تستهدف تطبيقات Spring Boot. توفر مجموعة من تقنيات الاستغلال، والحمولات (payloads)، وقوائم المراجعة الأمنية لإجراء تحليل الثغرات. يتميز المشروع بقدرات لتشغيل تنفيذ الكود عن بُعد من خلال ناقلات الحقن، وحمولات إلغاء التسلسل (deserialization)، وملفات الإعدادات الضارة. يتضمن ماسحاً ضوئياً لاكتشاف متغيرات البيئة المكشوفة وتفاصيل التوجيه الداخلي الناتجة عن نقاط النهاية التي تم إعدادها بشكل خاطئ، بالإضافة إلى طرق لاستخراج البيانات الحساسة والأسرار بنص عادي عبر تحليل تفريغ الذاكرة (heap dump). تدعم مجموعة الأدوات تقييمات الأمان للصندوق الأسود (black-box) وتحليل ثغرات إطار العمل، بما في ذلك تعيين إصدارات التبعيات لتحديد نوافذ الثغرات المحتملة.

    Provides a collection of crafted input strings designed to trigger unintended code execution via injection vulnerabilities.

    Javarcespring-actuator-vulnerabilityspring-boot-vulnerability
    عرض على GitHub↗6,136
  • audi-1/sqli-labsالصورة الرمزية لـ Audi-1

    Audi-1/sqli-labs

    5,791عرض على GitHub↗

    sqli-labs هي مجموعة من تطبيقات الويب الضعيفة عمداً وبيئات الاختبار المصممة لممارسة تحديد واستغلال ثغرات حقن SQL. تعمل كمختبر تعليمي للأمن السيبراني حيث يمكن للمستخدمين تجربة استغلال قواعد البيانات في بيئة خاضعة للرقابة. توفر البيئة وحدات متخصصة لاختبار مجموعة واسعة من ناقلات الهجوم، بما في ذلك الحقن القائم على الخطأ، والحقن الأعمى القائم على المنطق البولي، والحقن القائم على الوقت. تغطي بشكل خاص تقنيات متقدمة مثل حقن الدرجة الثانية، والاستعلامات المكدسة، والهجمات التي تستهدف رؤوس HTTP. يتضمن المشروع أيضاً تمارين تركز على تجاوز مرشحات الأمان وتجاوز جدران حماية تطبيقات الويب من خلال تقنيات مثل تجريد التعليقات وعدم تطابق المعاوقة. تسمح هذه السيناريوهات بمحاكاة اختبار الاختراق الواقعي وتدقيق أمن قواعد البيانات.

    Provides exercises for extracting database information using boolean logic and time-based response delays.

    PHP
    عرض على GitHub↗5,791
  • epinna/tplmapالصورة الرمزية لـ epinna

    epinna/tplmap

    4,169عرض على GitHub↗

    tplmap هي أداة أمنية مصممة لاكتشاف واستغلال ثغرات حقن القوالب من جانب الخادم (Server-Side Template Injection). تعمل كماسح آلي لتحديد سياقات محركات القوالب المعرضة للخطر وتوفر إطار عمل لتحقيق تنفيذ الأوامر عن بُعد. تركز الأداة على ترجمة الطلبات عالية المستوى إلى صيغة برمجية خاصة بالمحرك لتنفيذ أوامر نظام التشغيل وتجاوز بيئات الحماية (sandboxes) الخاصة بالتطبيقات. كما تتيح الوصول إلى نظام الملفات عن بُعد، مما يسمح للمستخدمين بقراءة وكتابة ونقل الملفات بين الجهاز المحلي والخادم المستهدف. تشمل القدرات الإضافية إمكانية تشغيل خوادم محلية مصابة لمحاكاة بيئات معيبة للتحقق من الحمولات (payloads). يدعم المشروع أيضاً التكامل مع وكلاء أمن الويب (web security proxies) لأتمتة حقن حمولات الاختبار في حركة المرور المعترضة.

    Identifies vulnerable engines by sending polyglot payloads and analyzing server response patterns.

    Python
    عرض على GitHub↗4,169
  • straight-tamago/misaka26الصورة الرمزية لـ straight-tamago

    straight-tamago/misaka26

    3,793عرض على GitHub↗

    This project is a framework and utility suite for iOS and iPadOS designed for privilege escalation, security exploitation, and system customization. It functions as a tool for performing sandbox escapes, exploiting kernel-level memory corruption and persistence bugs, and injecting unsigned code to bypass standard operating system security checks. The tool enables the modification of restricted system parameters and hidden configuration files to unlock device functionality. It allows for the installation of unauthorized application bundles and alternative app stores by bypassing code signing r

    Injects unsigned application bundles into protected system partitions by bypassing code signing.

    عرض على GitHub↗3,793
  • pwntester/ysoserial.netالصورة الرمزية لـ pwntester

    pwntester/ysoserial.net

    3,735عرض على GitHub↗

    ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl

    Creates specialized payloads designed to read sensitive files or write data to the target file system.

    C#
    عرض على GitHub↗3,735
  • mbechler/marshalsecالصورة الرمزية لـ mbechler

    mbechler/marshalsec

    3,691عرض على GitHub↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Produces crafted strings designed to test for injection vulnerabilities via JNDI lookups.

    Java
    عرض على GitHub↗3,691
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Injection Payloads

استكشف الوسوم الفرعية

  • Binary Injection TechniquesEmbeds malicious code into legitimate software packages to test system resilience. **Distinct from Injection Payloads:** Distinct from Injection Payloads: focuses on binary-level embedding rather than string-based injection.
  • Binary Injection Templates1 وسم فرعيEmbeds malicious code into legitimate binaries by modifying file structures and injecting execution hooks. **Distinct from Injection Payloads:** Distinct from Injection Payloads: focuses on binary-level structural modification rather than string-based injection.
  • Blind SQL InjectionsTechniques for testing database vulnerabilities by inferring information through true or false query responses.
  • Injection Analysis EnginesAutomated engines that analyze input reflection and context to identify potential injection vulnerabilities. **Distinct from Injection Payloads:** Distinct from generic Injection Payloads: focuses on the analysis engine logic rather than the payload collection itself.
  • Injection MappingTechniques for identifying specific injection contexts by analyzing server responses to polyglot payloads. **Distinct from Injection Payloads:** Focuses on the mapping/identification phase of the injection process, whereas Injection Payloads refers to the strings themselves.
  • LDAPPayloads used to test for security vulnerabilities within Lightweight Directory Access Protocol implementations.
  • LaTeX InjectionsPayloads designed to test for vulnerabilities related to the improper processing of LaTeX input.
  • Local File Inclusion PayloadsPayloads used to test for vulnerabilities where applications improperly include local files based on user input.
  • NoSQL2 وسوم فرعيةPayloads designed to test for injection vulnerabilities within NoSQL database query structures.
  • ORMPayloads used to test for injection vulnerabilities occurring within Object-Relational Mapping layers.
  • Protocol PayloadsSpecialized traffic sequences designed to test the processing requirements of specific network protocols. **Distinct from Injection Payloads:** Distinct from Injection Payloads: focuses on protocol-specific traffic sequences for stress testing rather than database or command injection exploits.
  • Remote File Inclusion PayloadsPayloads used to test for vulnerabilities where applications improperly include remote files based on user input.
  • SQLCollections of malicious input strings designed to exploit vulnerabilities in database query execution.
  • Stacked SQL InjectionsTechniques for executing multiple sequential database commands within a single injection point.
  • XPathSpecialized strings for testing XML path language injection vulnerabilities. **Distinct from Injection Payloads:** More specific than general Injection Payloads, focusing exclusively on the XPath language.