tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab
w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing
IIS Short Name Scanner - 2012-2023 & Still Giving...
fuxploider is an open source penetration testing tool that automates the process of detecting and exploiting file upload forms flaws. This tool is able to detect the file types allowed to be uploaded and is able to detect which technique will work best tu upload web shells or any malicious file…
Principalele funcționalități ale almandin/fuxploider sunt: Specialized Vulnerability Scanners, Vulnerability Exploitation Frameworks, Web Exploitation.
Alternativele open-source pentru almandin/fuxploider includ: epinna/tplmap — tplmap is a security tool designed for the detection and exploitation of server-side template injection… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… osandamalith/lfifreak — LFI Freak. tijme/angularjs-csti-scanner — Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x. irsdl/iis-shortname-scanner — IIS Short Name Scanner - 2012-2023 & Still Giving... knownsec/pocsuite3 — Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security…