Starlog — Page 27
// LATEST
Cybersecurity
JexBoss: The Blunt Instrument for Testing Legacy JBoss Deserialization Flaws
Developer Tools
Mapping the Invisible: How nmap-sap Exposes SAP Services That Standard Scanners Miss
Developer Tools
DotNetToJScript: Weaponizing .NET Assemblies Through Script Serialization
Developer Tools
Building Python-Toolkit-Quality Prompts in Go with go-prompt
Developer Tools
HashiCorp's Deprecated Best Practices Repo: A Time Capsule of Infrastructure-as-Code Evolution
Developer Tools
LinkFinder: Mining JavaScript for Hidden API Endpoints with Regex Precision
Automation
dig8: Building a DNS Crawler from Scratch in Go
Automation
dig8: Crawling DNS from the Root Servers Up
Cybersecurity
Inside CVE-2017-5638: Dissecting a Python Exploit for Apache Struts2's Most Devastating Vulnerability
Cybersecurity
Snallygaster: The Single-File Security Scanner That Finds What Developers Leave Behind
Cybersecurity
Exploiting .DS_Store Leaks: How ds_store_exp Turns macOS Metadata Into a Security Goldmine
Cybersecurity
GitHack: Weaponizing Exposed .git Folders to Reconstruct Source Code
Cybersecurity
Inside am0nsec/exploit: A Security Researcher's Personal Arsenal of Proof-of-Concept Exploits
Cybersecurity
foospidy/payloads: The 13GB Security Payload Archive Every Pentester Should Know About
Developer Tools
Building a Lightweight RPC Shell for Apache Axis2: When Metasploit Is Too Much
Cybersecurity
Statistically Likely Usernames: Why Horizontal Password Attacks Beat Vertical Every Time
Developer Tools
BaRMIe: Exploiting Java's Invisible Attack Surface in RMI Services
Automation
Building a Technology Detection Microservice with Wappalyzer API
Automation
GoGrabber: The Web Recon Tool That Screenshots Without Making Network Requests
Cybersecurity
PwnGitManager: Surgical Git Repository Extraction for Security Researchers
Cybersecurity
Inside can-i-take-over-xyz: The Crowdsourced Database Securing Subdomain Hygiene
Cybersecurity
Red-Teaming-Toolkit: A MITRE ATT&CK-Mapped Arsenal for Offensive Security Operations
Developer Tools
Parameth: Brute-Force Parameter Discovery for the APIs Nobody Documented
Developer Tools