Add tplmap, an automated SSTI exploitation tool in the style of SQLmap

This commit is contained in:
Meitar Moscovitz 2017-02-22 15:01:20 -05:00
parent 964675a96f
commit 6a14942a4e
No known key found for this signature in database
GPG Key ID: 07EFAA28AB94BC85

View File

@ -184,6 +184,7 @@ A collection of awesome penetration testing resources
#### Web exploitation
* [WPScan](https://wpscan.org/) - Black box WordPress vulnerability scanner
* [SQLmap](http://sqlmap.org/) - Automatic SQL injection and database takeover tool
* [tplmap](https://github.com/epinna/tplmap) - Automatic server-side template injection and Web server takeover tool
* [weevely3](https://github.com/epinna/weevely3) - Weaponized web shell
* [Wappalyzer](https://wappalyzer.com/) - Wappalyzer uncovers the technologies used on websites
* [cms-explorer](https://code.google.com/archive/p/cms-explorer/) - CMS Explorer is designed to reveal the the specific modules, plugins, components and themes that various CMS driven web sites are running.