SoheilKhodayari / Basta-COSI
A framework for the detection of COSI vulnerabilities / XS-Leaks
☆12Updated 2 years ago
Alternatives and similar repositories for Basta-COSI:
Users that are interested in Basta-COSI are comparing it to the libraries listed below
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆46Updated last year
- XS-Leak Browser Test Suite☆80Updated last year
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆74Updated 3 years ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆105Updated 4 months ago
- Source code for ACM CCS 2020 Paper PMForce: Systematically Analyzing postMessage Handlers at Scale☆17Updated 3 years ago
- Chrome extension to detect possible xsleaks☆12Updated 6 years ago
- Service-Now Article Bruteforcer☆16Updated 4 years ago
- Testability Pattern Catalogs for SAST☆30Updated 2 months ago
- This Burp extension helps you to find usages of postMessage and recvMessage☆15Updated 5 years ago
- List of Trusted Types bypasses☆93Updated last year
- ☆12Updated 2 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆49Updated 2 weeks ago
- The commands and scripts I used in the Live Recon Village talks☆38Updated 4 years ago
- This repository is an interactive collection of my solutions to various XSS challenges.☆12Updated 4 years ago
- ☆13Updated last year
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- ☆19Updated 6 years ago
- ☆49Updated 4 years ago
- CTF writeups☆30Updated 2 years ago
- Resources for Browser Security Research☆38Updated 2 years ago
- A framework for identifying vulnerabilities in VS Code extensions☆17Updated 9 months ago
- Dependency Confusion Security Testing Tool☆47Updated 2 years ago
- CVE PoCs☆21Updated 4 years ago
- ☆43Updated 9 months ago
- File system enumerator and monitor for Android and Ubuntu.☆17Updated 3 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated 2 months ago
- ☆44Updated 4 years ago
- Lab that will help you to understand how type juggling vulnerability works.☆22Updated 4 years ago