aurainfosec / jwt_key_confusionLinks
JWT key confusion attack, i.e. re-sigining RS256 to HS256
☆13Updated 3 years ago
Alternatives and similar repositories for jwt_key_confusion
Users that are interested in jwt_key_confusion are comparing it to the libraries listed below
Sorting:
- Tool for helping in the exploitation of path traversal vulnerabilities in Java web applications☆33Updated 3 years ago
- A tool for listing and extracting installed Android APKs and decrypted iOS IPAs (plus app storage) from rooted or jailbroken devices.☆34Updated 6 months ago
- ☆64Updated 2 years ago
- A Burp Suite extension that helps track and manage multiple sessions simultaneously by color-coding HTTP requests based on custom pattern…☆28Updated 11 months ago
- This tool is designed to test for file upload and XXE vulnerabilities by poisoning XLSX files.☆81Updated last year
- Formatify is a Burp Suite extension that instantly converts HTTP requests into multiple formats like cURL, Python, PowerShell, and more—s…☆28Updated last month
- Burp suite extension to find sensitive information by checking incoming text OR binary websocket messages☆55Updated 9 months ago
- Information Security Information From Web☆28Updated 3 months ago
- A demo PHP application used to exercise SQL injection techniques in a safe, local Docker environment☆44Updated last year
- ☆78Updated 4 months ago
- Payload generator to exfiltrate user cookies through the PHP info page bypassing the HttpOnly flag during XSS exploitation.☆20Updated last year
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated last year
- Help recon of hostnames from specific ASN or CIDR, thanks to Robtex and BGP.HE☆54Updated last year
- A tool for inspecting and analyzing mobile application storage files.☆47Updated 5 months ago
- Security Advisories☆34Updated this week
- A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.☆40Updated 2 weeks ago
- SALSA 💃⚡ - SALesforce Scanner for Aura (and beyond). Enumeration of vulnerabilities and misconfigurations against Salesforce endpoint.☆23Updated 9 months ago
- Web cache poisoning vulnerability scanner.☆71Updated 3 years ago
- Unicode characters that will translate a single character to multiple characters in domain names or TLD's☆48Updated 11 months ago
- ☆50Updated 9 months ago
- ☆34Updated 3 months ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆80Updated 2 years ago
- Mine URLs from Browser's Heap Snapshot for fun and profit☆64Updated 2 years ago
- DNS resolution tracing tool☆36Updated 4 years ago
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆42Updated 2 years ago
- Some simple scripts that I use during bug bounty hunting in Android Apps☆28Updated 9 months ago
- Simple PoC for demonstrating Race Conditions on Websockets☆55Updated 2 years ago
- The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489☆30Updated last year
- Exploiting XSS with Javascript/JPEG Polyglot (by @medusa_0xf)☆21Updated 3 years ago
- ☆31Updated 6 months ago