WSP-LAB / FUSE
A penetration testing tool for finding file upload bugs (NDSS 2020)
☆249Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for FUSE
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆344Updated last year
- Lab for exploring SSRF vulnerabilities☆245Updated 3 years ago
- WAF Bypass Cheatsheet☆209Updated 7 years ago
- When MVC magic turns black☆285Updated 4 years ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆243Updated 2 weeks ago
- A list of useful payloads for Web Application Security and Pentest/CTF☆292Updated 2 months ago
- List of Awesome Red Teaming Resources☆43Updated 6 years ago
- cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vul…☆139Updated 3 years ago
- SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities☆184Updated 3 years ago
- XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.☆138Updated 5 years ago
- Happy Hunting☆137Updated 5 years ago
- A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.☆511Updated 4 years ago
- ☆82Updated 4 years ago
- ☆398Updated 2 years ago
- Dockerfiles of CTF Challenges running on SniperOJ☆148Updated last year
- Here you can find mostly all disclosed h1 reports☆341Updated 2 years ago
- ☆127Updated 3 years ago
- HTTP file upload scanner for Burp Proxy☆482Updated 10 months ago
- A test suite built with Mocha/Chai to test for behavioral differences between image libraries for the web☆69Updated 4 years ago
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆336Updated 2 months ago
- Spring Boot Actuator (jolokia) XXE/RCE☆317Updated 4 years ago
- ☆278Updated 3 years ago
- SSRF plugin for burp Automates SSRF Detection in all of the Request☆552Updated 3 years ago
- Academic papers and articles that I read related to web hacking, fuzzing, etc. / 阅读过的Web安全方向、模糊测试方向的一些论文与阅读笔记☆361Updated 9 months ago
- PoC for CVE-2018-15133 (Laravel unserialize vulnerability)☆247Updated 8 months ago
- Burp Extension for a passive scanning JS files for endpoint links.☆162Updated 5 years ago
- Multi-language web CGI interfaces exploits.☆387Updated 2 years ago
- CVE 2021-21315 PoC☆154Updated 3 years ago
- A guided mutation-based fuzzer for ML-based Web Application Firewalls☆171Updated 8 months ago
- XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具☆260Updated 4 years ago