RUB-NDS / PrOfESSOS
PrOfESSOS is our open source implementation for fully automated Evaluation-as-a-Service for SSO. PrOfESSOS introduces a generic approach to improve the security of OpenID Connect implementations by systematically detecting vulnerabilities.
☆28Updated 2 years ago
Alternatives and similar repositories for PrOfESSOS:
Users that are interested in PrOfESSOS are comparing it to the libraries listed below
- ☆30Updated 2 years ago
- Open Security Summit 2018☆29Updated 4 years ago
- An extension for BurpSuite that highlights SSO messages in Burp's proxy window..☆116Updated 3 years ago
- OAuth plugin for Burp Suite Extender☆42Updated 6 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆56Updated 3 years ago
- ☆32Updated 9 years ago
- ☆21Updated 5 years ago
- ☆20Updated 6 years ago
- Index all certificates from certificate transparancy into Elasticsearch☆23Updated 7 years ago
- Compares the TLS configuration of a web server to the Mozilla TLS Profiles☆25Updated last year
- Framework for Automated Security Testing that is Scaleable and Asynchronous built on Microservices☆18Updated 8 years ago
- WebBorer is a directory-enumeration tool written in Go.☆44Updated last year
- ☆38Updated 4 years ago
- badbucket checks your s3 bucket for common misconfigurations☆23Updated 7 years ago
- ☆13Updated 7 years ago
- ☆12Updated 7 years ago
- Jaqen - Simple DNS rebinding☆71Updated 6 years ago
- The SSH Multiplex Backdoor Tool☆63Updated 5 years ago
- RFD Checker - security CLI tool to test Reflected File Download issues☆61Updated 5 years ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆33Updated 6 years ago
- ☆18Updated 4 years ago
- Transparently log all data passed into known JavaScript sinks - Sink Logger extension for Burp.☆49Updated 2 years ago
- This test suite contains over 40 different test cases that have proven to work with different mobile browsers in my research or testing S…☆30Updated 5 years ago
- ☆25Updated 3 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- Scripts that we use for pentesting☆42Updated 7 years ago
- Simple XXE test suite generated specifically for SAML interfaces☆22Updated 6 years ago
- TLS CBC Padding Oracle Checker☆52Updated 2 years ago
- A collection of scripts that I've written while pentesting.☆31Updated 6 years ago
- A PoC that shows that Web Vulnerabilities can indeed be interesting☆19Updated 6 years ago