prototype-pollution-explained
Ciphey
prototype-pollution-explained | Ciphey | |
---|---|---|
3 | 27 | |
75 | 17,053 | |
- | 2.2% | |
0.0 | 2.9 | |
over 1 year ago | about 1 month ago | |
JavaScript | Python | |
- | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
prototype-pollution-explained
-
Learning about ports and exploiting them
If you already know your NMAP command and switches, you can look up these sources to search what exploit to use depending on what port is open: - https://snyk.io/vuln/ - https://www.cvedetails.com/vulnerability-search.php - https://cve.mitre.org/cve/search_cve_list.html - https://nvd.nist.gov/vuln/search - https://www.rapid7.com/db/
-
Awesome Penetration Testing
Snyk Vulnerability DB - Detailed information and remediation guidance for vulnerabilities known by Snyk.
- Could someone please explain some to me how Prototype Pollution attack works with handlebars?
Ciphey
-
CyberChef from GCHQ: The Cyber Swiss Army Knife
I also discovered Ciphey. Neat little tool indeed, but it's being deprecated. It's mentioned in this issue[1] and being replaced with Ares[2]. Neither could decipher this strange encryption[3] I used it on :(
[1] https://github.com/Ciphey/Ciphey/issues/764
[2] https://github.com/bee-san/Ares
[3] "dEFLWWFKQWxRQW16RnkvbTZML0lsdz09" original text is "hacker"
- Ciphey – automated decryption/decoding/cracking tool
-
Email Obfuscation Rendered Almost Ineffective Against ChatGPT
Check Ciphey, I have used several times before and overall it’s great. https://github.com/Ciphey/Ciphey
- How do you identify common encodings?
- This is from the Netflix series Dark. I hope this isnt very hard to decrypt. I would love to see this cipher get decrypted. Also a good way of suggesting to watch this.
-
In CTFs, you'll often get a string of text to decode. Is there a good way to recognize how to decode it?
It can help you detect various encryption and encodings and even decrypt them. Ciphey
-
How do I install Ciphey on Windows 10?
I followed the steps here . I am running Python 3.10 (64). When I try to install Ciphey using the instructions, on my cmd prompt I get the following:
-
How do I get Ciphey to use more cores for decryption?
repo: https://github.com/Ciphey/Ciphey
-
tools for decrypting
if you're looking for something that would decrypt most well-known encodings/ciphers, there's ciphey. but no such thing exists to decrypt every known file type because, if it did, everyone would be using it.
- CyberChef – The Cyber Swiss Army Knife
What are some alternatives?
scapy - Scapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3.
CyberChef - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Cppcheck - static analysis of C/C++ code
juice-shop - OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
Metasploit - Metasploit Framework
CrackMapExec - A swiss army knife for pentesting networks
mitmproxy - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
jwt-cracker - Simple HS256, HS384 & HS512 JWT token brute force cracker.
github-readme-stats - :zap: Dynamically generated stats for your github readmes
Stockfish - A free and strong UCI chess engine
hacktricks - Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
eleventy-high-performance-blog - A high performance blog template for the 11ty static site generator.