Pinned Repositories
BurpExtenderForge
An Extender for Burp Suite allowing you to quickly craft Extenders in Burp.
chunkyTuna
An interactive webshell and HTTP tunnel for TCP connections using chunked transfer encoding
DemoExtender
Code used for a tutorial to get Netbeans GUI editor to work with a Burp Suite Extender
dns-parallel-prober
PoC for an adaptive parallelised DNS prober
git-fingerprint
Enumerate information from a target using git
HttpPwnly
"Repeater" style XSS post-exploitation tool for mass browser control. Primarily a PoC to show why HttpOnly flag isn't a complete protection against session hijacking via XSS
Indushell
PoC C&C for the Industroyer malware
IoTChecklist
Baseline IoT security checklist. Consider security as early in development as possible and reap the rewards.
psychoPATH
psychoPATH - hunting file uploads & LFI in the dark. This tool is a customisable payload generator designed for blindly detecting LFI & web file upload implementations allowing to write files into the webroot (aka document root). The "blind" aspect is the key here and is inherent to dynamic testing usually conducted with no access to the source code or the filesystem.
rdpupload
Python script which will type a file into an RDP session. For when drag and drop and disk mounting is not possible
Secarma Ltd's Repositories
SecarmaLabs/psychoPATH
psychoPATH - hunting file uploads & LFI in the dark. This tool is a customisable payload generator designed for blindly detecting LFI & web file upload implementations allowing to write files into the webroot (aka document root). The "blind" aspect is the key here and is inherent to dynamic testing usually conducted with no access to the source code or the filesystem.
SecarmaLabs/chunkyTuna
An interactive webshell and HTTP tunnel for TCP connections using chunked transfer encoding
SecarmaLabs/dns-parallel-prober
PoC for an adaptive parallelised DNS prober
SecarmaLabs/IoTChecklist
Baseline IoT security checklist. Consider security as early in development as possible and reap the rewards.
SecarmaLabs/Indushell
PoC C&C for the Industroyer malware
SecarmaLabs/HttpPwnly
"Repeater" style XSS post-exploitation tool for mass browser control. Primarily a PoC to show why HttpOnly flag isn't a complete protection against session hijacking via XSS
SecarmaLabs/git-fingerprint
Enumerate information from a target using git
SecarmaLabs/rdpupload
Python script which will type a file into an RDP session. For when drag and drop and disk mounting is not possible
SecarmaLabs/DemoExtender
Code used for a tutorial to get Netbeans GUI editor to work with a Burp Suite Extender
SecarmaLabs/BurpExtenderForge
An Extender for Burp Suite allowing you to quickly craft Extenders in Burp.
SecarmaLabs/explodingcan-checker
ExplodingCan Checker
SecarmaLabs/SSRS
SecarmaLabs/presentations
Starting to put presentations someplace centrally.
SecarmaLabs/shelling
SHELLING - a comprehensive OS command injection payload generator