PortSwigger / javascript-security
A Burp Suite extension which performs checks for cross-domain scripting against the DOM, subresource integrity checks, and evaluates JavaScript resources against threat intelligence data.
☆8Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for javascript-security
- ☆9Updated 2 years ago
- multiple password 'asher using Python’s hashlib☆14Updated 3 years ago
- Burp Suite Pro extension☆10Updated 7 years ago
- Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets☆42Updated last year
- Fork of https://github.com/PortSwigger/param-miner for header smuggling research☆12Updated 3 years ago
- A Burp Suite extension to add a custom header (e.g. JWT)☆18Updated 3 years ago
- Looking for JAR files that are vulnerable to Log4j RCE (CVE‐2021‐44228)?☆44Updated 2 years ago
- Kubernetes Scanner☆41Updated 2 years ago
- Burp Suite Extension - Trigger actions and reshape HTTP request and response traffic using configurable rules☆15Updated last month
- ☆19Updated 3 years ago
- A tool to parse, deduplicate, and query multiple port scans.☆57Updated last year
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆37Updated 3 years ago
- Reconness Agents Script☆32Updated 2 years ago
- Objectify-s3 is a tool that recursively checks AWS S3 buckets and objects for misconfigured permissions.☆15Updated 3 months ago
- Signatures for wraith used to detect secrets across various sources☆15Updated 2 years ago
- ☆10Updated 3 years ago
- A Burp Suite extension for headless, unattended scanning.☆36Updated 4 years ago
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆14Updated 6 years ago
- ☆29Updated 6 months ago
- Use rpc null sessions to retrieve machine list, domain admin list, domain controllers☆13Updated last year
- Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of …☆13Updated 7 months ago
- WebSocket Connection Smuggler☆44Updated 2 years ago
- Deploy multiple instances of Nessus in docker containers easily☆20Updated 3 years ago
- Install and upgrade projectdiscovery tools☆10Updated 2 years ago
- Burp Suite extension to discover assets from HTTP response.☆15Updated 3 years ago
- A python module for red teams to support the continuous recon of JavaScript files and HTML script blocks in an active web application.☆13Updated last year
- A CLI tool and library allowing to simply decode all kind of BigIP cookies.☆38Updated 4 years ago
- Adds extensibility to Burp by using a list of payloads to pattern match on HTTP responses highlighting interesting and potentially vulner…☆15Updated last year
- Related subdomains finder☆29Updated 2 years ago
- Multithreaded spraying of a password on all accounts of a domain.☆17Updated 4 months ago