Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor
Principalele funcționalități ale nil0x42/phpsploit sunt: Web Security Tools, Command And Control Frameworks, Exploitation Frameworks, Security Tools, Web Security Testing, Webshell Management Tools, Webshells.
Alternativele open-source pentru nil0x42/phpsploit includ: sqlmapproject/sqlmap — This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It… hightechsec/git-scanner — A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public. epinna/weevely3 — Weaponized web shell. ultimatehackers/xsstrike — XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web… wpscanteam/wpscan — WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress… zaproxy/zaproxy — OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in…
A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris
XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.