Advanced web exploitation — deserialization, race conditions, prototype pollution, OAuth.
Official PageCache key/unkeyed param discovery (Burp ext)
BApp Store in BurpRight-click > Guess params > Guess everythingPHP deserialization gadget chains
git clone https://github.com/ambionics/phpggc./phpggc -l; ./phpggc Laravel/RCE1 system idJava deserialization gadget generator
Download jarjava -jar ysoserial.jar CommonsCollections4 "id"SSTI detection and exploitation
git clone https://github.com/epinna/tplmappython3 tplmap.py -u "http://target/?name=*"JWT manipulation Burp extension
BApp StoreModify/resign JWTs directly in RepeaterOOB interaction server (like Collaborator)
go install github.com/projectdiscovery/interactsh/cmd/interactsh-client@latestinteractsh-clientHTTP request smuggling detector
git clone https://github.com/defparam/smugglerpython3 smuggler.py -u https://target.comAdvanced web testing proxy
Download portswigger.netHTTP Smuggler extension, Turbo Intruder, JWT Editor