DataDog / vulnerable-java-applicationLinks
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).
☆21Updated 11 months ago
Alternatives and similar repositories for vulnerable-java-application
Users that are interested in vulnerable-java-application are comparing it to the libraries listed below
Sorting:
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆106Updated last year
- Damn Vulnerable Cloud Application☆207Updated 7 years ago
- Blogpost series showcasing interesting cloud - web app security bugs☆49Updated 2 years ago
- Create notes during a security code review in VSCode 📝 Import your favorite SAST tool findings 🛠️ and collaborate with others 🤝☆141Updated 3 months ago
- Damn Vulnerable Java (EE) Application☆144Updated 2 years ago
- ☆127Updated last year
- GCP GOAT is the vulnerable application for learn the GCP Security☆70Updated 8 months ago
- ☆226Updated last month
- Purposely vulnerable Java application to help lead secure coding workshops☆191Updated last year
- Scan DockerHub images that match a keyword to find secrets.☆61Updated 4 years ago
- Cloud agnostic IAM permissions enumerator☆161Updated 9 months ago
- Tools to assess DNS security.☆153Updated last year
- boostsecurityio/lotp☆138Updated last week
- GCP cloud security CTF☆47Updated 7 months ago
- An extension to use Semgrep inside Burp Suite.☆89Updated 8 months ago
- ☆114Updated 2 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆282Updated 4 months ago
- Find CVE PoCs on GitHub☆160Updated 6 months ago
- A utility to convert your AWS CLI credentials into AWS console access.☆255Updated 5 years ago
- OWASP Foundation Web Respository☆37Updated 4 months ago
- PoC for CVE-Requested vulnerability in Amazon ECS (EC2 launch type) allowing cross-task IAM credential theft.☆45Updated 5 months ago
- Research on the enumeration of IAM permissions without logging to CloudTrail☆61Updated 4 years ago
- A simple script which implements different Cognito attacks such as Account Oracle or Priviledge Escalation☆109Updated last year
- NotSoCereal: A Deserialization exploit playground☆54Updated 4 years ago
- Workshop given at Hack in Paris 2019☆126Updated 2 years ago
- ☆17Updated 3 years ago
- Hide from the InstanceCredentialExfiltration GuardDuty finding by using VPC Endpoints☆121Updated 6 months ago
- Manager of 14 third-party sources comprising approximately 4,000 Semgrep rules 🗂☆98Updated last month
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- ☆35Updated 5 years ago