Konano / ReqsMinerLinks
[NDSS 2024] ReqsMiner is an innovative fuzzing framework developed to discover previously unexamined inconsistencies in CDN forwarding requests. The framework uses techniques derived from reinforcement learning to generate valid test cases, even with minimal feedback, and incorporates real field values into the grammar-based fuzzer.
☆23Updated last year
Alternatives and similar repositories for ReqsMiner
Users that are interested in ReqsMiner are comparing it to the libraries listed below
Sorting:
- ☆25Updated 3 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆47Updated 3 years ago
- Artifact for ICSE 2023☆50Updated 3 years ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆97Updated 2 years ago
- ☆16Updated 2 years ago
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆184Updated last year
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆73Updated last year
- A grey-box web application Fuzzer☆23Updated last year
- This project runs a Model Context Protocol (MCP) server that wraps the CodeQL query server. It enables tools like [Cursor](https://cursor…☆122Updated 8 months ago
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection☆80Updated 3 years ago
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆37Updated 5 years ago
- ☆18Updated last year
- Collect public CTF source code repo☆48Updated 4 years ago
- ☆64Updated 4 years ago
- A benchmark to evaluate taint analysis☆28Updated 3 years ago
- Fuzzing dictionaries for afl-fuzz/LibFuzzer☆91Updated 4 years ago
- A benchmark for Java gadget chain detecting algorithms.☆14Updated 5 months ago
- a dataflow analysis framework implemented in Go, like soot☆38Updated 3 years ago
- Challenge attachments for RWCTF 3rd.☆91Updated 4 years ago
- Taint analysis implementation based on Heros and Soot☆45Updated last year
- ☆27Updated last year
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆14Updated 4 months ago
- Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis☆82Updated last year
- A set of Code-ql/Joern queries to find vulnerabilities☆66Updated 4 years ago
- ☆38Updated 4 years ago
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications (NDSS 2022)☆25Updated last year
- YASA is an open-source static program analysis project. Its core innovation lies in a unified intermediate representation called UAST, d…☆207Updated 2 weeks ago
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆12Updated last year
- My CodeQL queries collection☆99Updated 2 years ago
- ☆22Updated 3 years ago