SecPriv / webspec
Towards Machine-Checked Analysis of Browser Security Mechanisms
☆11Updated 4 months ago
Related projects ⓘ
Alternatives and complementary repositories for webspec
- PoCs discovered through fuzzing which resulted in a CVE assignment.☆18Updated 4 years ago
- Automatic generator of YARA modules based in protocol buffers☆14Updated 2 months ago
- Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding In…☆18Updated 3 years ago
- Salesforce Policy Deviation Checker☆30Updated 4 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆13Updated 2 years ago
- ☆32Updated 4 months ago
- Proof of concept for an anti-phishing browser plugin, working by comparing pages screenshots with perceptual hashing algorithms.☆11Updated 2 years ago
- winAFL patch to enable network-based apps fuzzing☆37Updated 6 years ago
- The Binary Mutation code based on Uroboros☆14Updated 5 years ago
- A introductory workshop to getting started with fuzzing using american fuzzy lop (AFL)☆22Updated 5 years ago
- Open YARA scan- and search engine☆16Updated this week
- Abusing Cloudflare Workers to establish persistence and exfiltrate sensitive data at the edge.☆12Updated 2 years ago
- Avalanche is a document generator which uses context-free grammars to generate randomized outputs for fuzz-testing.☆32Updated 3 years ago
- Network based steganography based control channels and chat.☆8Updated 8 years ago
- A Platform for Testing Secure Coding/Config☆18Updated 5 years ago
- #INFILTRATE19 raptor's party pack.☆30Updated 10 months ago
- sslxray is an SSL/TLS scanning tool designed to detect a wide range of issues☆26Updated 6 years ago
- A medley of PoCs and exploits☆1Updated 5 years ago
- An auto-scoring capture-the-flag game focusing on TOCTOU vulnerabilities☆18Updated 4 years ago
- ☆13Updated 4 years ago
- ☆16Updated 3 years ago
- Regular expression Search on the command-line☆15Updated 7 months ago
- Work files for my blog post "Code Caving in a PE file.☆16Updated 7 years ago
- ☆9Updated 5 years ago
- Rekall Forensics and Incident Response Framework with rVMI extensions☆33Updated 3 years ago
- My attempt at writing exploit POCs for various CVEs☆16Updated 4 years ago
- The Multiplatform Linux Sandbox☆15Updated 10 months ago
- Vulnerable XSLT Console Application☆10Updated 7 years ago
- Dockerfiles for (un)popular fuzzers!☆28Updated 4 years ago