bkimminich / webappsec-nutshell
An ultra-compact intro (or refresher) to Web Application Security.
☆31Updated 6 years ago
Related projects ⓘ
Alternatives and complementary repositories for webappsec-nutshell
- Use burp's JS static code analysis on code from your local system.☆42Updated 7 years ago
- Collection of tools for web recon and enumeration.☆56Updated 9 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆36Updated 5 years ago
- Puny Domain Name Check☆36Updated 5 years ago
- The Unofficial Burp Extension for DNSDumpster.com☆70Updated 6 years ago
- Exploits and research stuffs☆54Updated last year
- Network based protocol fuzzer☆68Updated 2 years ago
- An example of obtaining RCE via Redis and CSRF☆77Updated 8 years ago
- Burp Notes Extension is a plugin for Burp Suite that adds a Notes tab. The tool aims to better organize external files that are created d…☆67Updated 6 months ago
- CSV injection Vulnerable Script.☆29Updated 7 years ago
- A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.☆25Updated 9 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆57Updated 2 years ago
- ☆13Updated 7 years ago
- General scripts for random stuff☆38Updated 3 years ago
- DNS Enumeration and Reconnaissance Tool☆37Updated 8 years ago
- Common Findings Database☆100Updated 5 years ago
- Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature☆25Updated 7 years ago
- Vulnerable Node.js Web Application to pratice with your pentesting skills☆21Updated 7 years ago
- Run DependencyCheck Against Your Orgs GitHub Repos.☆14Updated 6 years ago
- Fingerprint a web app using local files as the fingerprint sources☆36Updated 7 years ago
- ☆25Updated 7 years ago
- Tools for MITMing Yahoo! Mail with a Wifi Pineapple Mark V and Flash☆27Updated 8 years ago
- A reconnaissance tool that can quickly discover hostnames from a list of IP addresses.☆38Updated 13 years ago
- Demo server for testing Java deserialization payloads☆15Updated 8 years ago
- Highlight Burp proxy requests made by different browsers☆30Updated 7 years ago
- Passive recon / OSINT automation script☆40Updated 6 years ago
- This is sample code to demonstrate how one can use SQL Injection vulnerability to download local file from server in specific condition. …☆44Updated 7 years ago
- XXE vulnerability demo☆22Updated 10 years ago
- Docker repository for OWTF (64-bit Kali)☆33Updated 4 years ago