aurainfosec / jwt_key_confusionLinks
JWT key confusion attack, i.e. re-sigining RS256 to HS256
☆13Updated 3 years ago
Alternatives and similar repositories for jwt_key_confusion
Users that are interested in jwt_key_confusion are comparing it to the libraries listed below
Sorting:
- Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications☆32Updated 2 years ago
- Security Advisories☆34Updated last month
- A Burp Suite extension that helps track and manage multiple sessions simultaneously by color-coding HTTP requests based on custom pattern…☆27Updated 9 months ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆79Updated last year
- Chrome and Firefox extension that lists Amazon S3 Buckets while browsing☆124Updated 3 weeks ago
- Obtain GraphQL API schema despite disabled introspection!☆70Updated 4 years ago
- This is a Burp Suite extension that allows users to easily add web addresses to the Burp Suite scope.☆96Updated 8 months ago
- CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).☆135Updated 5 months ago
- xss development frameworks, with the goal of making payload writing easier.☆147Updated last year
- XSS Bypass☆30Updated last year
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆74Updated 2 years ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated last year
- Detect Program Bug Bounty☆43Updated 2 months ago
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆41Updated 2 years ago
- ☆74Updated 2 months ago
- For unpacking base64:ed "Save items"-content from Burp (From search + proxy history)☆54Updated 6 months ago
- ☆57Updated last year
- Check if domain has bug bounty program or not☆28Updated 2 years ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆78Updated last year
- A list of threat sinks used in the manual security source code review for application security☆73Updated 2 years ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆44Updated last year
- Content-Security-Policy (CSP) Bypass Techniques☆68Updated 4 years ago
- A simple plugin to export JS files from one or multiple targets☆43Updated last year
- Alternative to XSS Hunter for blind XSS.☆51Updated 2 years ago
- BurpSuite using the document and some extensions☆70Updated 5 years ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆98Updated last week
- Web cache poisoning vulnerability scanner.☆71Updated 3 years ago
- A browser bookmark to show hidden fields and enable disabled fields on a web page☆20Updated last year
- Formatify is a Burp Suite extension that instantly converts HTTP requests into multiple formats like cURL, Python, PowerShell, and more—s…☆27Updated 4 months ago
- ☆47Updated 7 months ago