PortSwigger / research-labsLinks
This repository contains a number of insecure self-hosted applications that allows interested security engineers to test vulnerabilities found by Portswigger Research team.
☆23Updated last month
Alternatives and similar repositories for research-labs
Users that are interested in research-labs are comparing it to the libraries listed below
Sorting:
- ☆81Updated 8 months ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆141Updated 6 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆99Updated last year
- ☆63Updated 2 years ago
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆69Updated 2 weeks ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆141Updated 11 months ago
- Golang tool which helps dropping the irrelevant entries from your ffuf result file.☆137Updated 9 months ago
- ☆167Updated 3 years ago
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆25Updated last month
- ☆67Updated 2 years ago
- Awesome MXSS ??☆52Updated 8 months ago
- A collection of utilities for building extensions using Burp's Montoya API☆50Updated last year
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- Extract JavaScript files from burp suite project with ease.☆90Updated 3 years ago
- Burp Extension that copies a request and builds a FFUF skeleton☆111Updated last year
- Useful configurations for the DomLogger++ extension☆35Updated 9 months ago
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆52Updated 4 months ago
- Same Origin XSS challenge☆61Updated 3 years ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆67Updated last year
- BChecks collection for Burp Suite Professional☆98Updated last year
- Wordlist to bruteforce for LFI☆124Updated 5 years ago
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆50Updated 2 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆32Updated 3 months ago
- A Burp Suite Extension for parsing Project Files from the CLI.☆87Updated 9 months ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆61Updated last week
- PP-finder Help you find gadget for prototype pollution exploitation☆164Updated 10 months ago
- Obtain GraphQL API schema despite disabled introspection!☆68Updated 4 years ago
- Improve automated and semi-automated active scanning in Burp Pro☆61Updated 3 weeks ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- Automated JavaScript Debugging Tool using CDP - Automatically sets breakpoints for specified strings/patterns in JavaScript code☆90Updated 6 months ago