DistriNet / BugHogLinks
Powerful framework for pinpointing bug lifecycles in web browsers.
☆24Updated this week
Alternatives and similar repositories for BugHog
Users that are interested in BugHog are comparing it to the libraries listed below
Sorting:
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆112Updated last month
- A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozi…☆125Updated 2 weeks ago
- A framework for the detection of COSI vulnerabilities / XS-Leaks☆14Updated 2 years ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆52Updated 2 years ago
- List of Trusted Types bypasses☆102Updated last year
- Puppeteer based crawler to measure email and password exfiltration☆25Updated 3 years ago
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆16Updated 9 months ago
- XS-Leak Browser Test Suite☆85Updated last year
- ☆16Updated 4 years ago
- TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.☆66Updated 2 months ago
- Prototype Pollution exploits collection☆34Updated 4 years ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆76Updated 3 years ago
- Python's handling of NaN is....interesting?broken?...this project illustrates the issue☆13Updated 3 years ago
- A collection of client-side libraries with HTML injection vulnerabilities and DOM clobbering gadgets.☆37Updated 2 months ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆57Updated 6 months ago
- The commands and scripts I used in the Live Recon Village talks☆39Updated 4 years ago
- Labs from our workshop "Demystifying the server-side".☆17Updated 3 years ago
- ☆83Updated last week
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Proof of Concepts for unsafe deserialization in Ruby☆17Updated last year
- 🗂 Knowledge Base on the Security of Chromium Extensions (https://extensions.neplox.security)☆19Updated 9 months ago
- Awesome MXSS ??☆54Updated last year
- Testability Pattern Catalogs for SAST☆31Updated 8 months ago
- A web security research tool for DOM testing☆24Updated this week
- A collection of Semgrep rules which followed security guidelines for .NET and Java.☆24Updated 4 years ago
- Client-Side Prototype Pollution Tools☆85Updated 4 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆33Updated 8 months ago
- A Node.js vulnerability finding tool.☆96Updated 2 months ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆20Updated last year
- XS-Leaks Wiki☆169Updated 5 months ago