4ARMED / sri-check
Python script for finding resource tags without subresource integrity.
☆32Updated 7 months ago
Alternatives and similar repositories for sri-check
Users that are interested in sri-check are comparing it to the libraries listed below
Sorting:
- WebSocket Connection Smuggler☆45Updated 2 years ago
- ☆30Updated last year
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆18Updated 7 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆38Updated 4 years ago
- Tools for auditing WAFS☆19Updated 3 years ago
- LogSnare: A playground for testing, preventing, and logging IDOR vulnerabilities.☆31Updated last year
- Security checks for your researches☆33Updated 4 years ago
- ☆23Updated 2 years ago
- Take domains on stdin and output them on stdout if they get resolved☆33Updated 2 years ago
- Objectify-s3 is a tool that recursively checks AWS S3 buckets and objects for misconfigured permissions.☆15Updated 9 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆29Updated last year
- Make exploiting race conditions in web applications highly efficient and ease-of-use.☆23Updated last year
- ☆31Updated 2 years ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆12Updated 3 years ago
- Penetration Testing Methodology - short notes☆11Updated 9 years ago
- A tool to parse, deduplicate, and query multiple port scans.☆59Updated last year
- Target practice for ffuf☆64Updated 3 years ago
- Python's handling of NaN is....interesting?broken?...this project illustrates the issue☆13Updated 3 years ago
- ☆71Updated 3 years ago
- Burp plugin for the 1Password session protocol for use by security researchers.☆67Updated 5 months ago
- Piper Burp Suite Extender plugin☆14Updated last month
- List of fresh and validated DNS resolvers updated every 12h.☆22Updated 2 weeks ago
- Research on abusing GitLab Runners☆26Updated 4 years ago
- Jumpstart multiple WebSocket servers quickly☆31Updated 3 years ago
- swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.☆58Updated 2 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated 8 months ago
- ☆21Updated 7 years ago
- A command-line utility for auditing DNS configuration using Zonemaster API☆30Updated last year
- ☆52Updated 6 months ago
- Contains all my research and content produced regarding the log4shell vulnerability☆31Updated 3 years ago