cispa / http-conformanceLinks
Code for our 2024 ACM AsiaCCS Paper "Who's Breaking the Rules? Studying Conformance to the HTTP Specifications and its Security Impact"
☆15Updated 11 months ago
Alternatives and similar repositories for http-conformance
Users that are interested in http-conformance are comparing it to the libraries listed below
Sorting:
- ☆25Updated 3 years ago
- ☆41Updated 2 years ago
- FuzzCache: Optimizing Web Application Fuzzing Through Software-Based Data Cache (ACM CCS 2024)☆16Updated 10 months ago
- Holistic Concolic Execution for Dynamic Web Applications via Symbolic Interpreter Analysis (IEEE S&P 2024)☆12Updated 11 months ago
- QUICforge is an experimental python tool for request forgery attacks with QUIC☆23Updated 3 years ago
- [NDSS 2024] ReqsMiner is an innovative fuzzing framework developed to discover previously unexamined inconsistencies in CDN forwarding re…☆21Updated last year
- 一个搜索网络安全领域顶会论文的小工具☆88Updated last month
- A neurosymbolic framework for vulnerability detection in code☆221Updated last week
- YuraScanner☆49Updated 6 months ago
- Corax for Java: A general static analysis framework for java code checking.☆255Updated 9 months ago
- ☆27Updated last year
- Grammar-based HTTP/2 fuzzer with mutation ability☆47Updated 3 years ago
- Collection of community-driven CodeQL query, library and extension packs☆182Updated this week
- Atropos: Effective Fuzzing of Web Applications for Server-Side Vulnerabilities☆71Updated last year
- ☆14Updated 2 years ago
- ☆28Updated 3 years ago
- 本项目通过大模型联动爬虫,检索Github上所有存有有价值漏洞信息与漏洞POC或规则信息的项目,并自动识别项目的目录结构、Readme信息后进行总结分析并分类,所汇总的项目可以帮助安全行业从业者收集漏洞信息、POC信息、规则等。☆140Updated last year
- ☆28Updated 3 years ago
- A structure-aware grey box fuzzer based on modeling the input processing logic.☆171Updated 10 months ago
- ODGen is a JavaScript Static Analysis tool to detect multiple types of vulnerabilities in Node.js packages.☆155Updated last year
- MCPCorpus is a comprehensive dataset for analyzing the Model Context Protocol (MCP) ecosystem, containing ~14K MCP servers and 300 MCP cl…☆19Updated last week
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection☆79Updated 2 years ago
- ☆18Updated 2 years ago
- ☆29Updated 4 months ago
- A declarative static analysis tool for jvm bytecode based Datalog like CodeQL☆339Updated last year
- The repository has collected about 10,000 malicious pypi packages. This dataset is the work of the ASE 2023 paper "An Empirical Study of…☆100Updated 3 weeks ago
- ☆19Updated 2 months ago
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages☆135Updated 2 years ago
- Effective ReDoS Detection by Principled Vulnerability Modeling and Exploit Generation☆14Updated last month
- ☆182Updated last month