16 dépôts
Collections of crafted strings designed to test for injection vulnerabilities across various database and execution contexts.
Explore 16 awesome GitHub repositories matching security & cryptography · Injection Payloads. Refine with filters or upvote what's useful.
This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i
Supplies a diverse library of payloads tailored for testing vulnerabilities where applications improperly process remote file inclusions.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
Provides extensive collections of injection payloads for testing application resilience against unexpected data.
MHDDoS is a command-line utility designed for volumetric stress testing and infrastructure resilience assessment. It functions as a comprehensive framework for simulating high-volume network and application layer traffic to evaluate the capacity and stability of web services and network infrastructure. The tool distinguishes itself through its ability to generate complex, protocol-specific traffic patterns and raw packet structures. By employing dynamic header randomization and specialized payload injection, it simulates diverse request behaviors intended to test the effectiveness of security
Generates specialized traffic sequences tailored to exploit the unique processing requirements of different network and application layer protocols.
XSStrike is an automated security scanning engine designed for web application discovery, input
Uses pattern matching to identify how user input is reflected in the response and determine the context of potential injection points.
Routersploit is a penetration testing framework designed for the security assessment of embedded network devices and routers. It functions as a comprehensive tool for auditing hardware configurations and testing network protocols to identify and verify security vulnerabilities. The framework utilizes a modular plugin architecture that allows for the dynamic loading of exploit and scanner modules. It provides a centralized command interface that manages target state and executes controlled payloads, enabling the automation of security testing across diverse network hardware. The platform cove
Crafts and transmits protocol-specific network packets to interact with device services and verify security flaws.
TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a
Embeds malicious code into legitimate software packages and binaries to test system resilience.
fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s
Provides specific payloads to test for remote file inclusion vulnerabilities.
fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i
Supplies crafted strings used to test for injection vulnerabilities across various execution contexts.
UACME is a set of specialized tools designed to audit security configurations, escalate user privileges, and circumvent access control restrictions on Windows systems. It functions as a utility for executing commands with elevated privileges by bypassing User Account Control restrictions. The project includes a configuration auditor used to extract and analyze system settings to identify security misconfigurations and vulnerabilities. It provides a collection of techniques for gaining administrative rights on a host. The toolset covers a wide range of privilege escalation and security auditi
Injects shellcode or binaries into legitimate system processes to evade security monitoring.
AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co
Provides techniques for exploiting NoSQL operator injection to bypass authentication and extract data.
SpringBootVulExploit est une collection d'outils de scan et d'audit conçus pour identifier les vulnérabilités, les fuites d'informations et les vecteurs d'exécution au sein des frameworks d'application Java, ciblant spécifiquement les applications Spring Boot. Il fournit une suite de techniques d'exploitation, de payloads et de checklists de sécurité pour effectuer une analyse de vulnérabilité. Le projet propose des fonctionnalités pour déclencher l'exécution de code à distance via des vecteurs d'injection, des payloads de désérialisation et des fichiers de configuration malveillants. Il inclut un scanner pour détecter les variables d'environnement exposées et les détails de routage interne causés par des endpoints mal configurés, ainsi que des méthodes pour extraire des données sensibles et des secrets en texte clair via l'analyse de heap dumps. L'ensemble d'outils prend en charge les évaluations de sécurité en boîte noire et l'analyse de vulnérabilité des frameworks, y compris le mappage des versions de dépendances pour identifier les fenêtres de vulnérabilité potentielles.
Provides a collection of crafted input strings designed to trigger unintended code execution via injection vulnerabilities.
sqli-labs est une collection d'applications web intentionnellement vulnérables et d'environnements sandbox conçus pour s'entraîner à l'identification et à l'exploitation de vulnérabilités par injection SQL. Il sert de laboratoire d'éducation en cybersécurité où les utilisateurs peuvent expérimenter des exploits de base de données dans un cadre contrôlé. L'environnement fournit des modules spécialisés pour tester un large éventail de vecteurs d'attaque, y compris les injections basées sur les erreurs, les injections aveugles booléennes et les injections basées sur le temps. Il couvre spécifiquement des techniques avancées telles que les injections de second ordre, les requêtes empilées et les attaques ciblant les en-têtes HTTP. Le projet inclut également des exercices axés sur l'évasion des filtres de sécurité et le contournement des pare-feu d'applications web via des techniques comme le retrait de commentaires et l'inadéquation d'impédance. Ces scénarios permettent la simulation de tests d'intrusion réels et d'audits de sécurité de bases de données.
Provides exercises for extracting database information using boolean logic and time-based response delays.
tplmap est un outil de sécurité conçu pour la détection et l'exploitation de vulnérabilités d'injection de templates côté serveur (SSTI). Il fonctionne comme un scanner automatisé pour identifier les contextes de moteurs de template vulnérables et fournit un framework pour parvenir à l'exécution de code à distance. L'outil se concentre sur la traduction de requêtes de haut niveau en syntaxe spécifique au moteur pour exécuter des commandes système et contourner les sandboxes d'applications. Il permet en outre l'accès au système de fichiers distant, autorisant les utilisateurs à lire, écrire et transférer des fichiers entre une machine locale et un serveur cible. Les fonctionnalités supplémentaires incluent la possibilité de lancer des serveurs vulnérables locaux pour simuler des environnements défectueux afin de vérifier les payloads. Le projet prend également en charge l'intégration avec des proxies de sécurité web pour automatiser l'injection de payloads de test dans le trafic intercepté.
Identifies vulnerable engines by sending polyglot payloads and analyzing server response patterns.
This project is a framework and utility suite for iOS and iPadOS designed for privilege escalation, security exploitation, and system customization. It functions as a tool for performing sandbox escapes, exploiting kernel-level memory corruption and persistence bugs, and injecting unsigned code to bypass standard operating system security checks. The tool enables the modification of restricted system parameters and hidden configuration files to unlock device functionality. It allows for the installation of unauthorized application bundles and alternative app stores by bypassing code signing r
Injects unsigned application bundles into protected system partitions by bypassing code signing.
ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl
Creates specialized payloads designed to read sensitive files or write data to the target file system.
Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu
Produces crafted strings designed to test for injection vulnerabilities via JNDI lookups.