AvalZ / WAF-A-MoLE
A guided mutation-based fuzzer for ML-based Web Application Firewalls
☆171Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for WAF-A-MoLE
- Grammar-based HTTP/1 fuzzer with mutation ability☆243Updated 3 weeks ago
- AutoSpear☆54Updated 10 months ago
- cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vul…☆139Updated 3 years ago
- An HTTP Response fuzzer to find Vulnerabilities in Security Scanners☆26Updated 5 months ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆69Updated 2 years ago
- A penetration testing tool for finding file upload bugs (NDSS 2020)☆249Updated 3 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- DNSpooq - dnsmasq cache poisoning (CVE-2020-25686, CVE-2020-25684, CVE-2020-25685)☆98Updated 3 years ago
- A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻☆120Updated 2 years ago
- A Python3 module to assist in fuzzing web applications☆57Updated 10 months ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆344Updated 2 years ago
- ☆82Updated 4 years ago
- A Python implementation that facilitates finding timeless timing attack vulnerabilities.☆121Updated last year
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆62Updated 3 years ago
- A source code static analysis platform for AppSec enthusiasts.☆204Updated last month
- Machine Learning WAF Based☆92Updated 4 years ago
- Compiled dataset of Java deserialization CVEs☆60Updated 4 years ago
- AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.☆39Updated last year
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆121Updated last year
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆90Updated 11 months ago
- OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.☆110Updated last year
- DNS rebinding toolkit☆250Updated last year
- DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source☆106Updated 5 years ago
- ☆175Updated 2 weeks ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆169Updated 3 weeks ago
- A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会☆164Updated 5 years ago
- ☆27Updated 2 years ago
- Monitoring exploits & references for CVEs☆229Updated 11 months ago
- Fuzzing dictionaries for afl-fuzz/LibFuzzer☆88Updated 3 years ago
- Black box fuzzer for web applications☆404Updated 4 months ago