This is your work, valued

Denver, CO

Wyatt Dahlenburg

Expert
@wdahlenburg

Security Researcher and Developer

interactsh-collaborator. Burpsuite plugin for Interact.sh

234

VhostFinder. Identify virtual hosts by similarity comparison

142

werkzeug-debug-console-bypass. Werkzeug has a debug console that requires a pin. It's possible to bypass this with an LFI vulnerability or use it as a local privilege escalation vector.

66

CVESearch. Query various sources for CVE proof-of-concepts

51

spring-gateway-demo. Sample Spring application to Demonstrate the Gateway Actuator

49

pyhprof. Parse HPROF files from the Spring Boot Heapdump Actuator

30

canary. CLI tool written in Go to generate Canary Tokens from https://canarytokens.org

13

Hounds. Chromium based web crawler that identifies in-scope urls

13

LogicalFuzzingEngine. A Burpsuite extension written in Python to perform basic validation fuzzing

11

Chegg. A simple exploit on Chegg that was found and submitted on April 29, 2015

4

aws-native-rce. Collection of payloads to work with AWS services

3

Sourcerer. Ruby based utility to apply rules to url datasources and insert filtered results into a Sidekiq compatible Redis queue

2

nfsshell. Userspace NFS client shell

2

Traveling-Salesperson-Problem. Princeton Traveling Salesperson Problem solved with an O(N2) algorithm

2

Catching-Plagiarists. Java

2

HttpComparison. Compare raw HTTP responses to identify signficant differences

2

qsreplace. Accept URLs on stdin, replace all query string values with a user-supplied value

1

SlurpLogin. Generate Selenium IDE Test Cases via a Burpsuite Plugin

1

rogue-jndi. A malicious LDAP server for JNDI injection attacks

1

msf-rpc-client. Golang based RPC client to communicate with Metasploit. Based off Black Hat Go's example.

1

NeoPixelRpiWebServer. JavaScript

1