DataDog / vulnerable-java-applicationLinks
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).
☆20Updated 7 months ago
Alternatives and similar repositories for vulnerable-java-application
Users that are interested in vulnerable-java-application are comparing it to the libraries listed below
Sorting:
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆105Updated 8 months ago
- Damn Vulnerable Cloud Application☆199Updated 7 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- ☆126Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆137Updated 6 months ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆67Updated 4 months ago
- A utility to convert your AWS CLI credentials into AWS console access.☆244Updated 5 years ago
- boostsecurityio/lotp☆134Updated 5 months ago
- ☆113Updated 2 years ago
- ☆200Updated 11 months ago
- GCP cloud security CTF☆47Updated 3 months ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆122Updated 2 months ago
- Damn Vulnerable Java (EE) Application☆141Updated last year
- Purposely vulnerable Java application to help lead secure coding workshops☆187Updated last year
- Proof of concept code for Datadog Security Labs referenced exploits.☆444Updated last month
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆108Updated last year
- Cloud agnostic IAM permissions enumerator☆157Updated 5 months ago
- Unauthenticated enumeration of AWS, Azure, and GCP Principals☆244Updated 10 months ago
- Find CVE PoCs on GitHub☆153Updated 2 months ago
- ☆50Updated last year
- The AWS Enumerator was created for service enumeration and info dumping for investigations of penetration testers during Black-Box testin…☆229Updated 3 years ago
- A GraphQL enumeration and extraction tool☆133Updated 2 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆274Updated 3 weeks ago
- OWASP Foundation Web Respository☆37Updated this week
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 4 months ago
- Utility for downloading and mounting EBS snapshots using the EBS Direct API's☆86Updated 6 months ago
- Holds the public Hacking the Cloud CTFs.☆59Updated last year
- truffleproc — hunt secrets in process memory (TruffleHog & gdb mashup)☆119Updated 2 years ago
- Tools to assess DNS security.☆152Updated last year