Exploitation is probably everyone favorite portion of a penetration test. It is where we get to actually launch attacks. The scripts in this section will target vulnerabilities in the target and the leverage these to further our penetration.


TYPO3 CMS Insecure Randomness Exploit - REF: TYPO3-SA-2009-001 Detailed Advisory - c22.cc

Tools for attacking MySQL

Apache EXPECT Header XSS POC

Apache 413 Error Message XSS POC

Bash Web Parameter Fuzzer

XSS GET to POST

MySQL Blind SQL Injector

p0wnpr0xy - Proxy for SQLMap