Teebytes / TnT-Fuzzer
OpenAPI 2.0 (Swagger) fuzzer written in python. Basically TnT for your API.
☆111Updated 2 years ago
Alternatives and similar repositories for TnT-Fuzzer:
Users that are interested in TnT-Fuzzer are comparing it to the libraries listed below
- Compiled dataset of Java deserialization CVEs☆61Updated 4 years ago
- HTML5 WebSocket message fuzzer☆144Updated 6 years ago
- A pytest-inspired, DAST framework, capable of identifying vulnerabilities in a distributed, micro-service ecosystem through chaos enginee…☆220Updated 9 months ago
- A static byte code analyzer for Java deserialization gadget research☆241Updated 7 years ago
- DupeKeyInjector☆135Updated 2 years ago
- Manager of third-party sources of Semgrep rules 🗂☆78Updated 7 months ago
- JWT Fuzzer for BurpSuite. Adds an Intruder hook for on-the-fly JWT fuzzing.☆98Updated 5 years ago
- Externalize Java application access to protected resources as log messages.☆41Updated 9 months ago
- ☆107Updated 3 years ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆247Updated 4 months ago
- Static Token And Credential Scanner☆96Updated last year
- ☆70Updated 7 years ago
- JWT fuzzer☆105Updated 6 years ago
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆62Updated 4 years ago
- Fuzzing script for redirect URL validator☆49Updated 5 years ago
- ☆55Updated 8 years ago
- ☆181Updated 4 months ago
- An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions☆122Updated 7 years ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆71Updated 2 years ago
- Code Review Audit Script Scanner☆140Updated last year
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- ☆147Updated 3 years ago
- A fuzzing framework for network servers☆118Updated 6 years ago
- A collection of my Semgrep rules☆48Updated last year
- BSidesSF CTF 2019 release☆72Updated 2 years ago
- The OpenSSF CVE Benchmark consists of code and metadata for over 200 real life CVEs, as well as tooling to analyze the vulnerable codebas…☆141Updated 11 months ago
- Burp Suite extension for JAX-RS☆65Updated 7 years ago
- HTTPWookiee is an HTTP server and proxy stress tool (respect of RFC, HTTP Smuggling issues, etc). If you run an HTTP server project conta…☆50Updated 7 years ago
- Evenly distributes scanner load across targets☆84Updated 2 years ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago