DataDog / vulnerable-java-applicationLinks
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).
☆21Updated 11 months ago
Alternatives and similar repositories for vulnerable-java-application
Users that are interested in vulnerable-java-application are comparing it to the libraries listed below
Sorting:
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆106Updated last year
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- ☆127Updated last year
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆141Updated 3 months ago
- Damn Vulnerable Cloud Application☆207Updated 7 years ago
- boostsecurityio/lotp☆137Updated last week
- A utility to convert your AWS CLI credentials into AWS console access.☆255Updated 5 years ago
- ☆226Updated last month
- Find CVE PoCs on GitHub☆160Updated 6 months ago
- GCP GOAT is the vulnerable application for learn the GCP Security☆70Updated 8 months ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆121Updated 6 months ago
- Proof of concept code for Datadog Security Labs referenced exploits.☆449Updated 3 weeks ago
- GCP cloud security CTF☆47Updated 7 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆282Updated 4 months ago
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆109Updated last year
- Purposely vulnerable Java application to help lead secure coding workshops☆191Updated last year
- Cloud agnostic IAM permissions enumerator☆161Updated 9 months ago
- ☆114Updated 2 years ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 8 months ago
- Tools to assess DNS security.☆153Updated last year
- POC tool to create signed AWS API GET requests to bypass Guard Duty alerting of off-instance credential use via SSRF☆59Updated 2 years ago
- WAF bypass PoC☆50Updated 2 years ago
- OWASP Foundation Web Respository☆37Updated 4 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.☆155Updated last year
- Scan DockerHub images that match a keyword to find secrets.☆61Updated 4 years ago
- Kubernetes Pwnage for all☆57Updated 5 years ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- Utility for downloading and mounting EBS snapshots using the EBS Direct API's☆91Updated 10 months ago
- The AWS Enumerator was created for service enumeration and info dumping for investigations of penetration testers during Black-Box testin…☆244Updated 3 years ago
- Damn Vulnerable Java (EE) Application☆144Updated 2 years ago