SoheilKhodayari / JAW
JAW: A Graph-based Security Analysis Framework for Client-side JavaScript
☆105Updated 4 months ago
Alternatives and similar repositories for JAW:
Users that are interested in JAW are comparing it to the libraries listed below
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆45Updated last year
- Testability Pattern Catalogs for SAST☆30Updated 2 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- YuraScanner☆38Updated 2 months ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆95Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆49Updated 5 months ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆74Updated 3 years ago
- A framework for identifying vulnerabilities in VS Code extensions☆17Updated 9 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆43Updated 2 years ago
- XS-Leak Browser Test Suite☆80Updated last year
- Searcher for cross-site leaks (XS-Leaks)☆81Updated 2 years ago
- Artifact for ICSE 2023☆49Updated 2 years ago
- List of Trusted Types bypasses☆92Updated last year
- ☆48Updated last year
- ☆28Updated 2 years ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆154Updated last year
- Awesome MXSS ??☆49Updated 6 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆183Updated 2 months ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆250Updated 5 months ago
- A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozi…☆93Updated 2 weeks ago
- ☆17Updated 6 years ago
- ☆19Updated last week
- ObjLupAnsys is a tool to detect prototype pollution vulnerabilities in Node.js packages. This project is written in Python and JavaScript…☆23Updated 3 years ago
- Witcher is the first framework for using AFL to fuzz web applications.☆85Updated last year
- XBOW Validation Benchmarks☆84Updated 7 months ago
- Modular static malicious JavaScript detection system☆69Updated 4 years ago
- CTF write-ups☆82Updated 4 months ago
- ☆31Updated 6 months ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- 🐛 UCLA ACM Cyber's Fuzzing Lab☆81Updated 3 months ago