Golim / wcdeLinks
Implementation of the Web Cache Deception detection methodology presented in the paper "Web Cache Deception Escalates!"
☆25Updated last year
Alternatives and similar repositories for wcde
Users that are interested in wcde are comparing it to the libraries listed below
Sorting:
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆51Updated last year
- Same Origin XSS challenge☆64Updated 3 years ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆57Updated 5 months ago
- A collection of client-side libraries with HTML injection vulnerabilities and DOM clobbering gadgets.☆34Updated 3 weeks ago
- ☆17Updated 2 years ago
- Provides public bug bounty programs in-scope data that offer rewards and monitors public bug bounty programs assets.☆83Updated this week
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- Client-Side Prototype Pollution Tools☆85Updated 4 years ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆111Updated 2 weeks ago
- Awesome MXSS ??☆53Updated 11 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆52Updated 4 months ago
- This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a p…☆111Updated last year
- ☆57Updated 8 months ago
- TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.☆55Updated last month
- A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻☆127Updated 3 years ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆78Updated this week
- Expand urls into one url for each path depth☆33Updated 5 years ago
- ☆105Updated last year
- Directory scans☆83Updated last year
- Prototype Pollution exploits collection☆34Updated 4 years ago
- Modified Nuclei Templates Version to FUZZ Host Header☆50Updated 3 years ago
- ☆184Updated 11 months ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆19Updated last year
- PoC for XSS in org.webjars:swagger-ui [3.14.2, 3.36.2]☆53Updated 2 years ago
- A Burp Suite extension to extract datas from source code while browsing.☆160Updated last year
- Security Advisories☆34Updated 2 months ago
- ☆33Updated 4 years ago
- This repo contains solution for ctf challenges☆36Updated 9 months ago
- all domains and his subdoamins☆64Updated 4 years ago