cneill / appsec-resources
Resources for developers and security engineers to learn the ropes of application security
☆97Updated 6 years ago
Alternatives and similar repositories for appsec-resources:
Users that are interested in appsec-resources are comparing it to the libraries listed below
- ☆92Updated 6 years ago
- A regex based source code scanner.☆129Updated 7 years ago
- burpbuddy exposes Burp Suites's extender API over the network through various mediums, with the goal of enabling development in any langu…☆157Updated 6 years ago
- A Burp Plugin for Detecting Weaknesses in Content Security Policies☆164Updated last year
- ☆122Updated 6 years ago
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- Hodor! Fuzzer..☆128Updated 8 years ago
- A project designed to parse public source code repositories and find various types of vulnerabilities.☆191Updated 7 years ago
- This is a bundle of python and bash penetration testing tools for recon and information gathering.☆80Updated 9 years ago
- ☆45Updated 7 years ago
- PwnableWeb is a suite of web applications for use in information security training.☆87Updated 10 years ago
- Web Application Security☆125Updated 8 months ago
- The Unofficial Burp Extension for DNSDumpster.com☆70Updated 6 years ago
- A Github organization reconnaissance tool.☆216Updated last year
- A weekly challenge where we share some code and you find a bug in it.☆70Updated 9 years ago
- Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website☆138Updated 4 years ago
- The databases, API's and managers behind https://websecweekly.org☆50Updated 9 years ago
- PoC for an adaptive parallelised DNS prober☆44Updated 7 years ago
- Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature☆25Updated 7 years ago
- Public exploits (re)writed while learning.☆59Updated 11 years ago
- Hackerone disclosed report URL Aggregator☆29Updated 6 years ago
- psychoPATH - hunting file uploads & LFI in the dark. This tool is a customisable payload generator designed for blindly detecting LFI & w…☆141Updated 7 years ago
- A collection of all the lists, scripts and techniques I use while doing web application penetration tests.☆168Updated 8 years ago
- A tool for discovering subdomains via third party services and wordlists.☆75Updated 8 years ago
- Store Burp data and collaborate via git☆53Updated 5 years ago
- The Internetwache CTF 2016 repository☆73Updated 3 years ago
- Common Findings Database☆100Updated 5 years ago
- Proof-of-concept two-stage dropper generator that uses bits from external sources☆98Updated 7 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆56Updated 3 years ago
- Allows you to trace where inputs are reflected back to the user.☆37Updated 7 years ago