SoheilKhodayari / Basta-COSI
A framework for the detection of COSI vulnerabilities / XS-Leaks
☆12Updated last year
Related projects ⓘ
Alternatives and complementary repositories for Basta-COSI
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆40Updated last year
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆30Updated last year
- List of Trusted Types bypasses☆86Updated 7 months ago
- Source code for ACM CCS 2020 Paper PMForce: Systematically Analyzing postMessage Handlers at Scale☆17Updated 3 years ago
- A simple Google Protobuf Decoder for Burp☆42Updated 2 years ago
- Service-Now Article Bruteforcer☆16Updated 4 years ago
- Testability Pattern Catalogs for SAST☆29Updated 8 months ago
- This repository is an interactive collection of my solutions to various XSS challenges.☆11Updated 4 years ago
- The commands and scripts I used in the Live Recon Village talks☆38Updated 3 years ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆101Updated last week
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last year
- Labs from our workshop "Demystifying the server-side".☆17Updated 2 years ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆44Updated last week
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring parts☆78Updated last year
- ☆12Updated last year
- ☆44Updated 4 years ago
- Lab that will help you to understand how type juggling vulnerability works.☆22Updated 4 years ago
- Chrome extension to detect possible xsleaks☆12Updated 5 years ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆67Updated 3 years ago
- CircleCI log and security configuration automations☆22Updated 4 years ago
- This Burp extension helps you to find usages of postMessage and recvMessage☆15Updated 4 years ago
- Some simple scripts that I use during bug bounty hunting in Android Apps☆30Updated 5 months ago
- apkizer is a mass downloader for android applications for all available versions.☆46Updated 3 years ago
- Semgrep rules corresponding to the OWASP ASVS standard☆27Updated 4 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- A extension for collecting parameters☆25Updated 4 years ago
- WILSON Cloud Respwnder is a Web Interaction Logger Sending Out Notifications with the ability to serve custom content in order to appropr…☆51Updated 2 months ago
- ☆28Updated last month
- flask-webgoat is a deliberately-vulnerable application written with the Flask web framework.☆19Updated 4 months ago