cispa / xs-observations
Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"
☆12Updated last month
Related projects ⓘ
Alternatives and complementary repositories for xs-observations
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆44Updated last week
- List of Trusted Types bypasses☆86Updated 7 months ago
- ☆88Updated 11 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆40Updated last year
- Awesome MXSS ??☆45Updated last month
- XS-Leak Browser Test Suite☆73Updated 11 months ago
- Find XS-Leaks in the browser by diffing DOM-Graphs in two states☆14Updated 11 months ago
- Useful configurations for the DomLogger++ extension☆30Updated 2 months ago
- PP-finder Help you find gadget for prototype pollution exploitation☆138Updated 3 months ago
- Searcher for cross-site leaks (XS-Leaks)☆81Updated last year
- ☆65Updated last month
- ☆83Updated 5 months ago
- A collection of Server-Side Prototype Pollution gadgets and exploits☆134Updated 2 months ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆101Updated last week
- This repository is a one-stop shop for diving deep into the fascinating world of mXSS (mutations caused by browser quirks in HTML parsing…☆15Updated last month
- Cookie Crumbles: Breaking and Fixing Web Session Integrity☆23Updated last year
- XS-Leaks Wiki☆151Updated 3 months ago
- How GitHub Actions workflows can be hacked☆106Updated 3 months ago
- Challenges I wrote for various CTF competitions☆40Updated 4 months ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆30Updated last year
- ✨ Build a beautiful and simple website in literally minutes. Demo at https://beautifuljekyll.com☆21Updated last year
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- CTF write-ups☆80Updated 2 months ago
- A framework for the detection of COSI vulnerabilities / XS-Leaks☆12Updated last year
- Here i will post my writeups :)☆31Updated last year
- ☆56Updated last year
- A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs☆60Updated 4 months ago
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆52Updated last week
- No longer maintained. Timing attacks on a browsers cache to try to predict websites/subreddits that have been viewed☆10Updated 2 years ago