RUB-NDS / AutoLeak
Find XS-Leaks in the browser by diffing DOM-Graphs in two states
☆14Updated 11 months ago
Related projects ⓘ
Alternatives and complementary repositories for AutoLeak
- List of Trusted Types bypasses☆86Updated 7 months ago
- XS-Leak Browser Test Suite☆73Updated 11 months ago
- Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"☆12Updated last month
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆44Updated last week
- This Chromium extensions aims at supporting the analysis of single sign-on implementations, by offering semi-automated analysis and attac…☆27Updated last year
- ☆15Updated 3 years ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆40Updated last year
- CTF writeups☆30Updated 2 years ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- ☆28Updated 3 weeks ago
- XS-Leaks Wiki☆151Updated 3 months ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- Proof of Concepts for unsafe deserialization in Ruby☆14Updated last month
- ☆69Updated 3 years ago
- A curated list of awesome browser security learning material.☆130Updated 2 years ago
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆11Updated last year
- Updated version of the ProtoBurp Extension, with enhanced features and capabilities to encode and fuzz custom protobuf messages☆36Updated last year
- Informational Repository tracking times that real world bugs have come out of CTF challenges intentionally or otherwise☆58Updated last year
- The Paper Artifact Availability☆19Updated 2 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- PoC for iTerm2 CVEs CVE-2024-38396 and CVE-2024-38395 which allow code execution☆20Updated 5 months ago
- ☆19Updated last year
- ☆10Updated 2 weeks ago
- Prototype Pollution exploits collection☆30Updated 3 years ago
- Make exploiting race conditions in web applications highly efficient and ease-of-use.☆23Updated 6 months ago
- A collection of my Semgrep rules☆47Updated last year
- This repository is an interactive collection of my solutions to various XSS challenges.☆11Updated 4 years ago
- A simple Google Protobuf Decoder for Burp☆42Updated 2 years ago
- Electron Research☆70Updated 2 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆30Updated last year