BishopFox / json-interop-vuln-labs
Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"
☆200Updated last year
Alternatives and similar repositories for json-interop-vuln-labs:
Users that are interested in json-interop-vuln-labs are comparing it to the libraries listed below
- ☆168Updated 3 years ago
- A curated list of awesome browser security learning material.☆137Updated 2 years ago
- A simple SSRF-testing sheriff written in Go☆322Updated 2 months ago
- Predict Mongo ObjectIds☆127Updated 6 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- Content-Type Research☆550Updated 11 months ago
- ☆128Updated 4 years ago
- Client Side Prototype Pollution Scanner☆510Updated 2 years ago
- 🐙 Cross-document messaging security research tool powered by https://enso.security☆284Updated last year
- Adds a customizable "Send to..."-context-menu to your BurpSuite.☆151Updated 2 years ago
- ☆527Updated last year
- The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources☆127Updated 4 years ago
- ☆176Updated 2 months ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆297Updated last year
- Unofficial documentation for the great tool Param Miner☆176Updated 2 years ago
- XS-Leaks Wiki☆156Updated this week
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆347Updated 5 months ago
- A tool to perform Sequential Import Chaining☆255Updated 5 years ago
- A natural evolution of Burp Suite's Repeater tool☆194Updated 11 months ago
- Simple "postMessage logger" Chrome extension☆94Updated 4 years ago
- ☆666Updated 2 years ago
- List HackerOne private program assets☆150Updated 3 years ago
- DOM XSS scanner for Single Page Applications☆400Updated 6 months ago
- List of Trusted Types bypasses☆86Updated 9 months ago
- This repo contains all the injections mentioned in my talk and enumerators.☆121Updated last year
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆346Updated 2 years ago
- Continuous monitoring for JavaScript files☆219Updated 5 years ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆256Updated 2 years ago
- Automatic tool for DNS rebinding-based SSRF attacks☆295Updated 4 years ago
- ☆147Updated last year