libformatstr.py is a Python library designed to simplify format string exploitation during penetration testing and security research activities. The tool provides functionality to: - Replace memory addresses with specific values using format string vulnerabilities - Insert ROP (Return-Oriented Programming) chains at target memory locations - Automatically determine format string argument numbers and padding requirements - Generate payloads for format string attacks with customizable parameters - Handle both numeric values and string data in exploitation scenarios The library offers a programmatic interface for constructing format string exploits, allowing security researchers to specify target addresses, payload data, and exploitation parameters. It includes helper functions for pattern generation and argument number detection to streamline the exploitation process. The tool supports various exploitation scenarios including single DWORD replacement, ROP chain injection, and ordered memory writes with configurable start lengths and padding values.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
SharpEDRChecker scans system components to detect security products and tools.
Interactive online malware sandbox for real-time analysis and threat intelligence
SauronEye helps in identifying files containing sensitive data such as passwords through targeted directory searches.
An Azure Function that validates and relays Cobalt Strike beacon traffic based on Malleable C2 profile authentication.
A suite of tools for Wi-Fi network security assessment and penetration testing.
Explore the top million websites, ranked by referring subnets, and gain insights into online influence and popularity.
AHHHZURE is an automated deployment script that creates vulnerable Azure cloud lab environments for offensive security training and cloud penetration testing practice.
A digital archive of the internet, allowing users to capture and browse archived web pages.
Tool for enumerating proxy configurations and generating CobaltStrike-compatible shellcode.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.