Golim / wcde
Implementation of the Web Cache Deception detection methodology presented in the paper "Web Cache Deception Escalates!"
☆22Updated 8 months ago
Alternatives and similar repositories for wcde:
Users that are interested in wcde are comparing it to the libraries listed below
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆44Updated last year
- Same Origin XSS challenge☆56Updated 2 years ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- ☆36Updated last year
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 2 years ago
- Awesome MXSS ??☆47Updated 4 months ago
- ☆86Updated 9 months ago
- jws2pubkey tool☆38Updated 8 months ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆48Updated 3 months ago
- Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.☆57Updated 8 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- tetctf2020_amf_writeups☆23Updated 4 years ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆36Updated 2 weeks ago
- a repository of all the CTF challenges I've made for public events☆51Updated last year
- AutoSpear☆55Updated last year
- Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit☆76Updated 4 months ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆55Updated last year
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆56Updated last year
- Security Advisories☆32Updated last year
- Simple taint analyzer for PHP/WordPress using VKCOM/php-parser☆18Updated 2 years ago
- Wordlist to bruteforce for LFI☆123Updated 5 years ago
- Utility for creating ZipSlip archives☆69Updated 2 years ago
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆61Updated 7 months ago
- Mass querying whois records☆30Updated 3 years ago
- Chrome extension that finds DOM based XSS vulnerabilities☆71Updated 2 years ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆166Updated 2 weeks ago
- Proof of Concepts for unsafe deserialization in Ruby☆17Updated 4 months ago
- Enhanced 403 bypass header☆21Updated 2 years ago