cispa / http-conformance
Code for our 2024 ACM AsiaCCS Paper "Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security Impact"
☆11Updated 4 months ago
Alternatives and similar repositories for http-conformance:
Users that are interested in http-conformance are comparing it to the libraries listed below
- ☆24Updated 2 years ago
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆11Updated 4 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data Cache (ACM CCS 2024)☆10Updated 3 months ago
- QUICforge is an experimental python tool for request forgery attacks with QUIC☆21Updated 2 years ago
- ☆36Updated 2 years ago
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆63Updated 6 months ago
- [NDSS 2024] ReqsMiner is an innovative fuzzing framework developed to discover previously unexamined inconsistencies in CDN forwarding re…☆17Updated 7 months ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆64Updated last year
- A differential fuzzing framework for the QUIC protocol☆16Updated last year
- ☆27Updated 2 years ago
- Examples for Implementing cve-2023-44487 ( HTTP/2 Rapid Reset Attack ) Concept☆8Updated last year
- Witcher is the first framework for using AFL to fuzz web applications.☆80Updated last year
- ☆24Updated last year
- ☆23Updated 2 years ago
- ☆13Updated 2 years ago
- 一个搜索网络安全领域顶会论文的小工具☆85Updated 3 months ago
- FUGIO: Automatic Exploit Generation for PHP Object Injection Vulnerabilities☆93Updated last year
- Implementation of the Web Cache Deception detection methodology presented in the paper "Web Cache Deception Escalates!"☆22Updated 8 months ago
- Artifact for ICSE 2023☆47Updated 2 years ago
- ☆25Updated last year
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆152Updated last year
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆12Updated 2 months ago
- ☆122Updated 8 months ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆104Updated 2 months ago
- Collection of community-driven CodeQL query, library and extension packs☆135Updated last week
- ☆99Updated 3 weeks ago
- A structure-aware grey box fuzzer based on modeling the input processing logic.☆162Updated 4 months ago
- SQL / SQLI tokenizer parser analyzer☆184Updated 8 months ago