Repositories list
94 repositories
vulnerable-web-app
Publicxxe-injection
PublicA threat actor may interfere with an application's processing of extensible markup language (XML) data to view the content of a target's filesxslt-injection
PublicA threat actor may interfere with an application's processing of extensible stylesheet language transformations (XSLT) for extensible markup language (XML) to r…xml-injection
Publicos-command-injection
PublicA threat actor may inject arbitrary operating system (OS) commands on targetopen-redirect
PublicA threat actor may send a malicious redirect request for a vulnerable target to a victim; the victim gets redirected to a malicious website that threat actor co…- A threat actor may inject malicious content into webapp. The payload is not reflected in the HTTP request and response, then executed in the victim's browser
- A threat actor may inject malicious content into webapp. The payload is reflected in the HTTP request and response, then executed in the victim's browser
session-replay
PublicA threat actor may re-use a stolen or leaked session identifier to access the user's accountlocal-file-inclusion
Publicsession-fixation
PublicA threat actor may trick a user into using a known session identifier to log in. after logging in, the session identifier is used to gain access to the user's a…captcha-bypass
PublicA threat actor may bypass the Completely Automated Public Turing test to tell Computers and Humans Apart (captcha) by breaking the solving logic, human-assisted…remote-file-inclusion
PublicA threat actor may cause a vulnerable target to include/retrieve remote filesession-hijacking
PublicA threat actor may access the user's account using a stolen or leaked valid (existing) session identifierauthorization-bypass
PublicA threat actor may access the user's account using a stolen or leaked valid (existing) session identifier- A threat actor may perform unauthorized functions belonging to another user with a higher privileges level
- A threat actor may perform unauthorized functions belonging to another user with a similar privileges level
authentication-bypass
PublicA threat actor may gain access to data and functionalities by bypassing the target authentication mechanismsql-injection
PublicA threat actor may alter structured query language (SQL) query to read, modify and write to the database or execute administrative commands for further chained …blind-sql-injection
Publicblind-sql-injectionixora
Publicsocial-analyzer
PublicAPI, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websiteshoneypots
Public30 different honeypots in one package! (dhcp, dns, elastic, ftp, http proxy, https proxy, http, https, imap, ipp, irc, ldap, memcache, mssql, mysql, ntp, oracle…default-credential
PublicA threat actor may gain unauthorized access using the default username and passwordanalyzer
PublicAnalyze, extract and visualize features, artifacts and IoCs of files and memory dumps (Windows, Linux, Android, iPhone, Blackberry, macOS binaries, emails and m…
ProTip! When viewing an organization's repositories, you can use the
props. filter to filter by custom property.