CanardMandarin / csp-bypass
Need any help bypassing CSP ?
☆24Updated 4 years ago
Related projects ⓘ
Alternatives and complementary repositories for csp-bypass
- A collection of Server-Side Prototype Pollution gadgets and exploits☆133Updated 2 months ago
- Phar + JPG Polyglot generator and playground (CTF CODE)☆72Updated 5 years ago
- PP-finder Help you find gadget for prototype pollution exploitation☆138Updated 3 months ago
- Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.☆177Updated last month
- CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator☆270Updated last year
- Here i will post my writeups :)☆31Updated last year
- ctf writeups☆62Updated 2 years ago
- Challenges I wrote for various CTF competitions☆40Updated 4 months ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- Awesome MXSS ??☆45Updated last month
- CVE-2023-33733 reportlab RCE☆113Updated last year
- POC for CVE-2021-41091☆65Updated last year
- A PoC for the CVE-2022-44268 - ImageMagick arbitrary file read☆215Updated last year
- This tool is for letting you know how strong your disable_functions is and how you can bypass that.☆113Updated 5 years ago
- Some tips for Bug Bounty using LibreOffice☆33Updated this week
- A tool that recovers the public key used to sign JWT tokens☆107Updated last year
- A python module to explore the object tree to extract paths to interesting objects in memory.☆79Updated 8 months ago
- This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a p…☆101Updated 7 months ago
- Deriving RSA public keys from message-signature pairs☆270Updated 6 months ago
- ☆22Updated 3 years ago
- Find all libraries on cdn.js that pollute your prototype☆19Updated 2 years ago
- Same Origin XSS challenge☆56Updated 2 years ago
- a repository of all the CTF challenges I've made for public events☆50Updated last year
- PHP binary bugs advisory☆178Updated 2 years ago
- Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security☆103Updated 8 months ago
- All challenges from DiceCTF 2023☆69Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆43Updated last week
- A blazing fast Blind SQL Injection optimization and automation framework.☆118Updated last week
- ☆111Updated 2 years ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆59Updated 2 weeks ago