adamdoupe / enemy-of-the-stateLinks
This novel black-box web vulnerability scanner attempts to infer the state machine of the web application.
☆19Updated 5 years ago
Alternatives and similar repositories for enemy-of-the-state
Users that are interested in enemy-of-the-state are comparing it to the libraries listed below
Sorting:
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆15Updated 6 years ago
- Symbolic execution inspired PHP application scanner for code-path discovery☆34Updated 6 years ago
- Joern Workshops☆29Updated 10 months ago
- Result files from various fuzzing runs☆16Updated 4 years ago
- CFG and scripts for fuzzing the PHP interpreter with Domato☆28Updated 5 years ago
- Materials from Fuzzing Bay Area meetups☆57Updated 5 years ago
- Dockerfile for AFL++ and helpful other tools☆21Updated 5 years ago
- COVA - A static analysis tool to compute path conditions☆39Updated 5 months ago
- Protocol Inspection and State Machine Analysis☆23Updated 7 years ago
- This is the project of LearnAFL.☆28Updated 5 years ago
- A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.☆24Updated 6 years ago
- ACSAC 2018 paper: Towards Automated Generation of Exploitation Primitives for Web Browsers☆14Updated 7 years ago
- WinDbg script to spoof origin and url of a renderer process in Chrome☆25Updated 5 years ago
- ☆23Updated 6 years ago
- ☆19Updated 7 years ago
- ☆19Updated 9 years ago
- ☆29Updated 5 years ago
- Downloader for Firefox/jsshell/Thunderbird builds for fuzzing.☆43Updated 3 weeks ago
- This is an example library to show how to fuzz with AFL++ only the code modified by the last commit.☆17Updated 5 years ago
- Binary rewriting approach with fork server support to fuzz Java applications with afl-fuzz.☆90Updated 7 years ago
- ☆27Updated 2 years ago
- Testability Tarpits: the Impact of Code Patterns on the Security Testing of Web Applications (NDSS 2022)☆25Updated last year
- Materials from Fuzzing Bay Area meetups☆68Updated 5 years ago
- Default query sets for Joern☆26Updated 4 years ago
- Static data flow-based analysis of JavaScript files to detect syntactic clones☆23Updated 5 years ago
- Network and USB protocol fuzzing toolkit.☆69Updated 7 years ago
- Extract useful semantic from CVE descriptions usinig NLP☆25Updated 2 years ago
- A fuzzy parser for C/C++ that creates semantic code property graphs☆37Updated 5 years ago
- Toy implementation of a Automated Exploit Generation built on Angr; stiched using radare, pwntools, pyelftools, and Angrop.☆16Updated 3 years ago
- My Material for the HITB presentation☆35Updated 5 years ago