SirAppSec / vuln-node.js-express.js-app
A Very Vulnerable Node.js Express.js Web Application and API. Used for testing Security tools, Application security and penetration testing. Using Swagger, Sqlite, Sequelize.
☆25Updated 2 months ago
Related projects ⓘ
Alternatives and complementary repositories for vuln-node.js-express.js-app
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆54Updated last year
- Intentionaly very vulnerable API with bonus bad coding practices☆40Updated 9 months ago
- Target practice for ffuf☆58Updated 3 years ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆97Updated 9 months ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆83Updated 5 months ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆111Updated last year
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- NotSoCereal: A Deserialization exploit playground☆50Updated 2 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆178Updated 2 years ago
- Filters and highlights Proxy HTTP history for requests with potentially vulnerable parameters☆23Updated 11 months ago
- HTTP parameter discovery suite.☆59Updated 4 years ago
- ☆100Updated last year
- Password spraying tool and Bloodhound integration☆212Updated last year
- Trickest Workflow for discovering log4j vulnerabilities and gathering the newest community payloads.☆112Updated 2 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆169Updated 2 weeks ago
- Source Code Management Attack Toolkit☆210Updated 2 years ago
- A NoSQL Injectable Node App☆41Updated 3 years ago
- Let's check if your target is vulnerable for client side prototype pollution.☆63Updated 10 months ago
- A simple remote scanner for Atlassian Jira☆118Updated last year
- A simple Node.js Express REST app with some OWASP vulnerabilities.☆16Updated 3 months ago
- Find CVE PoCs on GitHub☆137Updated last year
- HackBar plugin for Burpsuite☆25Updated 3 years ago
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆155Updated 2 weeks ago
- ☆121Updated 3 years ago
- A GraphQL enumeration and extraction tool☆128Updated last year
- Repository of CVE found by OCD people☆73Updated 4 months ago
- Workshop given at Hack in Paris 2019☆121Updated last year
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆252Updated 4 months ago
- Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.☆170Updated 10 months ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆83Updated last month