Contrast-Security-OSS / NodeTestBenches
A collection of intentionally vulnerable test bench applications for testing the Contrast Security Node Agent.
☆9Updated 5 months ago
Alternatives and similar repositories for NodeTestBenches:
Users that are interested in NodeTestBenches are comparing it to the libraries listed below
- My solution for GitHub Security Lab CTF 4: CodeQL and Chill - The Java Edition☆19Updated 4 years ago
- Burp Wiener API (Legacy)☆59Updated last year
- 2 web tasks from ZeroNights HackQuest 2016☆50Updated 8 years ago
- Custom Fortify SCA rules to detect common JSSE certification validation flaws☆11Updated 9 years ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- ☆14Updated last year
- An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations…☆25Updated 2 years ago
- A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities☆60Updated 8 years ago
- Burp Suite extension for JAX-RS☆65Updated 8 years ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- A tool for detecting XML External Entity (XXE) vulnerabilities in Java applications☆72Updated 10 years ago
- Deprecated: Please visit https://github.com/github/codeql instead.☆81Updated 3 years ago
- Java Deserialization☆26Updated 8 years ago
- Extension providing view with filtering capabilities for both complete and incomplete requests from all burp tools.☆48Updated 4 years ago
- Collection of python helper API's for interacting with LGTM.com in ways the official API doesn't support.☆24Updated 3 years ago
- YSOSERIAL Integration with burp suite☆40Updated 3 years ago
- A collection of various scripts and automations to simplify Checkmarx SAST and IAST setup and use☆14Updated 6 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆122Updated 7 years ago
- check cmd execute☆13Updated 8 years ago
- Proof of concept exploit, showing how to do bytecode injection through untrusted deserialization with Spring Framework 4.2.4☆116Updated 5 years ago
- Spring messaging STOMP protocol RCE☆113Updated 7 years ago
- RCE Exploit PoC for Spring based RESTFul APIs using XStream as Unmarshaler☆20Updated 11 years ago
- Burp extension to passively scan for applications revealing software version numbers☆31Updated 10 months ago
- Hackerone disclosed report URL Aggregator☆29Updated 6 years ago
- Trigger automated Acunetix scans as part of your web application's build process☆32Updated 8 months ago
- Script to test if a server is vulnerable to the JetLeak vulnerability☆144Updated 8 years ago
- ☆27Updated 4 years ago
- A Java serializer in JavaScript☆81Updated 6 years ago
- Burp Suite extension to passively scan for applications revealing server error messages☆66Updated last year
- Automated Python Code Injection Tool☆88Updated 3 years ago