cezary-sec / awesome-browser-security
A curated list of awesome browser security learning material.
☆130Updated 2 years ago
Related projects ⓘ
Alternatives and complementary repositories for awesome-browser-security
- ☆175Updated 2 weeks ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- Workshop given at Hack in Paris 2019☆121Updated last year
- Awesome information for WebSockets security research☆252Updated 2 years ago
- List of Trusted Types bypasses☆86Updated 7 months ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆243Updated 3 weeks ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- ☆158Updated 3 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆169Updated 3 weeks ago
- ☆128Updated 3 years ago
- A GraphQL enumeration and extraction tool☆128Updated last year
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- PP-finder Help you find gadget for prototype pollution exploitation☆138Updated 3 months ago
- A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻☆120Updated 2 years ago
- Find CVE PoCs on GitHub☆137Updated last year
- AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.☆39Updated last year
- Same Origin XSS challenge☆56Updated 2 years ago
- An Intentionally designed Vulnerable Android Application built in Kotlin.☆232Updated 2 years ago
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- Client Side Prototype Pollution Scanner☆511Updated 2 years ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.☆252Updated 4 months ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆26Updated 3 years ago
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring parts☆78Updated last year
- ☆146Updated last year
- Manager of third-party sources of Semgrep rules 🗂☆76Updated 4 months ago
- A Node.js vulnerability finding tool.☆95Updated 4 years ago
- A collection of my Semgrep rules☆47Updated last year
- 🐙 Cross-document messaging security research tool powered by https://enso.security☆281Updated last year