SoheilKhodayari / DOMClobbering
DOM Clobbering Wiki, Browser Testing, and Payload Generation
☆49Updated last week
Alternatives and similar repositories for DOMClobbering:
Users that are interested in DOMClobbering are comparing it to the libraries listed below
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Awesome MXSS ??☆49Updated 7 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆46Updated last year
- Same Origin XSS challenge☆56Updated 3 years ago
- Challenges I wrote for various CTF competitions☆41Updated 9 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆185Updated 3 months ago
- Here i will post my writeups :)☆32Updated 2 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- List of Trusted Types bypasses☆93Updated last year
- This repo contains solution for ctf challenges☆34Updated 5 months ago
- This repository is a one-stop shop for diving deep into the fascinating world of mXSS (mutations caused by browser quirks in HTML parsing…☆18Updated 2 months ago
- Find all libraries on cdn.js that pollute your prototype☆18Updated 2 years ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆88Updated 6 months ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆44Updated last month
- ✨ Build a beautiful and simple website in literally minutes. Demo at https://beautifuljekyll.com☆21Updated 2 years ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆27Updated 4 years ago
- a repository of all the CTF challenges I've made for public events☆53Updated last year
- ☆62Updated 2 years ago
- ☆39Updated 3 months ago
- XS-Leak Browser Test Suite☆80Updated last year
- LFI to RCE via phpinfo() assistance or via controlled log file☆66Updated 2 years ago
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆66Updated 2 months ago
- Blog about HTTP Request Smuggling, including a demo application.☆26Updated 3 years ago
- Utility for creating ZipSlip archives☆72Updated 2 years ago
- A cheatsheet for exploiting server-side SVG rasterization.☆30Updated 2 years ago
- Updated version of the ProtoBurp Extension, with enhanced features and capabilities to encode and fuzz custom protobuf messages☆36Updated last year
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- ☆79Updated 7 months ago
- ☆18Updated last month
- ☆56Updated 3 years ago