Konano / ReqsMiner
[NDSS 2024] ReqsMiner is an innovative fuzzing framework developed to discover previously unexamined inconsistencies in CDN forwarding requests. The framework uses techniques derived from reinforcement learning to generate valid test cases, even with minimal feedback, and incorporates real field values into the grammar-based fuzzer.
☆17Updated 7 months ago
Alternatives and similar repositories for ReqsMiner:
Users that are interested in ReqsMiner are comparing it to the libraries listed below
- ☆24Updated 2 years ago
- The fuzzing framework named SHADOWFUZZER to find clientside vulnerabilities when processing incoming MQTT messages.☆20Updated last year
- Artifact for ICSE 2023☆46Updated 2 years ago
- FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data Cache (ACM CCS 2024)☆10Updated 3 months ago
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆63Updated 6 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- ☆24Updated last year
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆93Updated last year
- Auto-generated CodeQL rules for matching CVE vulnerabilities and variants.☆162Updated 5 months ago
- ☆15Updated last year
- 更好的包装pwntools,提高编写pwn题exp效率的工具☆27Updated 3 years ago
- a dataflow analysis framework implemented in Go, like soot☆33Updated 2 years ago
- A benchmark to evaluate taint analysis☆30Updated 2 years ago
- 以太坊单合约交易调试工具☆16Updated 3 years ago
- KernJC: Automated Vulnerable Environment Generation for Linux Kernel Vulnerabilities (Best Practical Paper Award of RAID 2024)☆45Updated last month
- ☆24Updated 5 years ago
- 快速对自己项目中引入的第三方开源库进行1day patch检索,patch数据每天晚上11点更新☆20Updated 3 years ago
- Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis☆74Updated 11 months ago
- ☆36Updated 2 years ago
- S&P2023 Paper☆39Updated 2 years ago
- Low-level RASP: Protecting Applications Implemented in High-level Programming Languages☆57Updated last year
- A small PoC for the recent RCE found in the Goahead Webserver prior to version 5.1.5.☆21Updated 3 years ago
- Taint analysis implementation based on Heros and Soot☆44Updated 9 months ago
- Collate and collect binary related materials, including papers, tools, etc. Now,there are the following categories: 1、Fuzzing☆56Updated 5 years ago
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆12Updated 2 months ago
- A set of Code-ql/Joern queries to find vulnerabilities☆57Updated 3 years ago
- 《深入理解Semgrep》Finding vulnerabilities with Semgrep.☆44Updated last year
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆11Updated 4 months ago
- ☆17Updated 4 years ago
- My CodeQL queries collection☆96Updated last year