BishopFox / json-interop-vuln-labs
Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"
☆201Updated 2 years ago
Alternatives and similar repositories for json-interop-vuln-labs:
Users that are interested in json-interop-vuln-labs are comparing it to the libraries listed below
- A curated list of awesome browser security learning material.☆140Updated 2 years ago
- ☆536Updated this week
- ☆184Updated 4 months ago
- ☆173Updated 3 years ago
- Client Side Prototype Pollution Scanner☆518Updated 2 years ago
- List of Trusted Types bypasses☆91Updated 11 months ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆300Updated 2 years ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆248Updated 4 months ago
- A simple SSRF-testing sheriff written in Go☆324Updated 4 months ago
- This repo contains all the injections mentioned in my talk and enumerators.☆123Updated last year
- Burp Suite extension that offers a toolkit for testing GraphQL endpoints.☆191Updated 7 months ago
- Adds a customizable "Send to..."-context-menu to your BurpSuite.☆153Updated 2 years ago
- ☆128Updated 4 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆347Updated 2 years ago
- ☆150Updated last year
- A natural evolution of Burp Suite's Repeater tool☆195Updated last year
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆256Updated 2 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- Burp Suite Extension to monitor new scope☆196Updated 3 years ago
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆352Updated 7 months ago
- Continuous monitoring for JavaScript files☆218Updated 5 years ago
- Unofficial documentation for the great tool Param Miner☆178Updated 2 years ago
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆128Updated 4 years ago
- Predict Mongo ObjectIds☆129Updated 6 years ago
- PP-finder Help you find gadget for prototype pollution exploitation☆152Updated 7 months ago
- DNS rebinding toolkit☆251Updated last year
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆27Updated 4 years ago
- Simple "postMessage logger" Chrome extension☆96Updated 4 years ago
- 🐙 Cross-document messaging security research tool powered by https://enso.security☆287Updated last year
- Automatic tool for DNS rebinding-based SSRF attacks☆298Updated 4 years ago