SpiderLabs/microphisher
µphisher spear phishing tool (reference implementation)
Discovered public repositories for SpiderLabs in the GitHub catalog.
µphisher spear phishing tool (reference implementation)
cribdrag - an interactive crib dragging tool for cryptanalysis on ciphertext generated with reused or predictable stream cipher keys
A tool to parse UPnP descriptor XML files and generate SOAP control requests for use with Burp Suite or netcat
The Magical Code Injection Rainbow! MCIR is a framework for building configurable vulnerability testbeds. MCIR is also a collection of configurable vulnerability testbeds.
Public repository.
Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created during penetration testing.
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
A configurable OS shell command injection vulnerability testbed
Ettercap Project http://ettercap.sourceforge.net
Updated version of the 2010 KoreLogic password cracking rules for John the Ripper
An OCSP responder written in Ruby. Uses r509 and Sinatra.
r509 is a ruby library that allows you to create/parse CSRs, issue certs off arbitrary CAs, parse certs, create CRLs, run an OCSP responder, and much more
OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
Inject beef hooks into HTTP traffic and track hooked systems from cmdline
CryptOMG is a configurable CTF style test bed that highlights common flaws in cryptographic implementations.
SpiderLabs shared Nmap Tools
A repository of tools and scripts related to malware analysis
XSSmh - A configurable Cross-Site Scripting testbed
This is a stub project to store some PoC code for bypassing proxy controls
A configurable XPath/XML injection testbed
Perl/Python modules for interfacing with Metasploit MSGRPC
A configurable SQL injection test-bed
"Broken NAT" - A suite of tools focused on detecting/exploiting/fixing publicly available BNAT scenerios
Arduino-based network monitor
Workaround for the vulnerability identified by TWSL2011-007 or CVE-2008-0228 - iOS x509 Certificate Chain Validation Vulnerability
A JBoss script for obtaining remote shell access
Ruby bindings for the yara file analysis and classification library
NMAP NSE that enumerates VNC authentication types
A Java Server Faces (JSF) testing tool for decoding view state and creating view state attack vectors.
Performs method enumeration and interrogation against flash remoting end points.
A reconnaissance tool that can quickly discover hostnames from a list of IP addresses.
A program to monitor network traffic and detect unauthorized sessions.
TCP session interception and injection framework