bahruzjabiyev / t-reqs
Grammar-based HTTP/1 fuzzer with mutation ability
☆243Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for t-reqs
- ☆175Updated 2 weeks ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆56Updated 10 months ago
- A structure-aware HTTP fuzzing library☆206Updated last year
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆344Updated 2 years ago
- A curated list of awesome browser security learning material.☆130Updated 2 years ago
- Black box fuzzer for web applications☆404Updated 4 months ago
- When MVC magic turns black☆286Updated 4 years ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆69Updated 2 years ago
- jws2pubkey tool☆37Updated 5 months ago
- ☆319Updated 2 years ago
- AutoSpear☆54Updated 10 months ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆169Updated 3 weeks ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆133Updated 2 months ago
- A guided mutation-based fuzzer for ML-based Web Application Firewalls☆171Updated 8 months ago
- cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vul…☆139Updated 3 years ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆90Updated 11 months ago
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆112Updated 7 months ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆40Updated last year
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆252Updated 4 months ago
- Find CVE PoCs on GitHub☆137Updated last year
- Finding Java gadget chains with CodeQL☆159Updated 3 months ago
- RCE 0-day for GhostScript 9.50 - Payload generator☆540Updated 3 years ago
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆121Updated last year
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆59Updated 2 weeks ago
- Compiled dataset of Java deserialization CVEs☆60Updated 4 years ago
- DNS rebinding toolkit☆250Updated last year
- Collection of community-driven CodeQL query, library and extension packs☆74Updated last week
- Same Origin XSS challenge☆56Updated 2 years ago