SonarQubeCommunity / sonar-fortify
Fortify SCA Plugin for SonarQube
☆14Updated 3 years ago
Alternatives and similar repositories for sonar-fortify:
Users that are interested in sonar-fortify are comparing it to the libraries listed below
- A technique for developing Fortify structural rules and characterization rules.☆14Updated 5 years ago
- Baseline IoT security checklist. Consider security as early in development as possible and reap the rewards.☆30Updated 7 years ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆122Updated 7 years ago
- Custom Fortify SCA rules to detect common JSSE certification validation flaws☆11Updated 9 years ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- Java Deserialization☆26Updated 8 years ago
- Identify vulnerable libraries in Maven dependencies☆46Updated 2 years ago
- poc or exp of some famous vulnerability☆14Updated 11 years ago
- Java taint propagation for java. Define tainted sources, sanitizer methods and sinks via aspects.☆28Updated 6 years ago
- java unserialize vulnerability payload☆21Updated 6 years ago
- Repository to hold materials for DefCon_RESTing presentation by Dinis, Abe and Alvaro☆53Updated 11 years ago
- POC for XStream RCE☆13Updated 11 years ago
- A tiny Java agent that blocks attacks against unsafe deserialization☆83Updated 7 years ago
- Repository to showcase various configuration recipes with various technologies☆35Updated 2 years ago
- A tool for detecting XML External Entity (XXE) vulnerabilities in Java applications☆72Updated 10 years ago
- 2 web tasks from ZeroNights HackQuest 2016☆50Updated 8 years ago
- A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs☆54Updated 8 years ago
- Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.☆144Updated 8 years ago
- Web Input Vector Extractor Teaser☆132Updated 3 years ago
- AndroidManifest.xml security auditor☆71Updated 12 years ago
- MOSEC-X-PLUGIN 后端API服务☆24Updated 4 years ago
- All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities☆27Updated 3 years ago
- General Open Architecture Security Questionnaire☆32Updated last year
- XSS payloads for edge cases☆34Updated 6 years ago
- Yet Another Source Code Analyzer☆184Updated 3 years ago
- Just A GITBOOK Ver of WIKI, translating to CHINESE☆32Updated last year
- A fast generative fuzzer for HTTP☆17Updated 6 years ago
- 💣 REST and SOAP web API fuzzer☆26Updated 8 years ago
- Fortify SonarQube Plugin☆22Updated 4 years ago
- Code Pulse is a real-time code coverage tool for penetration testing activities☆122Updated 2 years ago