cispa / xs-observations
Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"
☆14Updated 4 months ago
Alternatives and similar repositories for xs-observations:
Users that are interested in xs-observations are comparing it to the libraries listed below
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆10Updated 9 months ago
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆49Updated 2 weeks ago
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆15Updated 3 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆46Updated last year
- List of Trusted Types bypasses☆93Updated last year
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Awesome MXSS ??☆49Updated 7 months ago
- ☆85Updated 10 months ago
- XS-Leak Browser Test Suite☆80Updated last year
- ☆106Updated last year
- This repository is a one-stop shop for diving deep into the fascinating world of mXSS (mutations caused by browser quirks in HTML parsing…☆18Updated 2 months ago
- Useful configurations for the DomLogger++ extension☆34Updated 8 months ago
- Puppeteer based crawler to measure email and password exfiltration☆22Updated 2 years ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆187Updated 3 months ago
- OmniCrawl is a web measurement tool that allows for recording of web requests and JavaScript browser API accesses on multiple platforms.☆25Updated last year
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆105Updated 5 months ago
- 🛠️ Workflows created by the community☆67Updated this week
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆59Updated last week
- ☆48Updated this week
- Obtain GraphQL API schema despite disabled introspection!☆52Updated 3 years ago
- ☆32Updated 10 months ago
- xss development frameworks, with the goal of making payload writing easier.☆141Updated 9 months ago
- ☆62Updated 2 years ago
- ☆16Updated 3 years ago
- Chrome extension for automating CSPT discovery☆82Updated 2 weeks ago
- Prototype Pollution exploits collection☆33Updated 3 years ago
- ☆65Updated 2 years ago
- HTTP/2 Last Frame Synchronization (also known as Single Packet Attack) low Level Library / Tool based on Scapy + Exploit Timing Attacks☆175Updated 6 months ago
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆66Updated this week
- PP-finder Help you find gadget for prototype pollution exploitation☆159Updated 9 months ago