cweb / unicode-hax
A library to assist in security-testing Unicode enabled applications during fuzzing, XSS, SQLi, etc.
☆42Updated 7 years ago
Related projects ⓘ
Alternatives and complementary repositories for unicode-hax
- An interactive OOB XXE data exfiltration tool☆90Updated 7 years ago
- Demo server for testing Java deserialization payloads☆15Updated 8 years ago
- An example of obtaining RCE via Redis and CSRF☆77Updated 8 years ago
- Exploit insecure crossdomain.xml files.☆26Updated 7 years ago
- BlindRef serves as the basis for an automated Blind-Based XXE Exploitation Framework☆26Updated 7 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆36Updated 5 years ago
- Jaqen - Simple DNS rebinding☆71Updated 6 years ago
- ☆70Updated 7 years ago
- This test suite contains over 40 different test cases that have proven to work with different mobile browsers in my research or testing S…☆31Updated 5 years ago
- HTML5 WebSocket message fuzzer☆144Updated 5 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 10 years ago
- Tests for different parsers from Ruby, Python, .NET, PHP, Perl, Java☆56Updated 8 years ago
- Evenly distributes scanner load across targets☆82Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆34Updated 8 years ago
- Extension adds a new tab in Burp Suite called Extractor☆42Updated 5 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆110Updated 5 years ago
- Improved decoder for Burp Suite☆135Updated 3 years ago
- Burp Suite extension to generate Intruder payloads using Radamsa☆87Updated 7 years ago
- ReconJSON is a project dedicated to creating a flexible and consistent JSON format across popular recon tools.☆102Updated 5 years ago
- A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.☆25Updated 9 years ago
- A Burp Extension to test applications for vulnerability to the Web Cache Deception attack☆135Updated 3 years ago
- Dirbuster plugin for Burp Suite☆70Updated 7 years ago
- Pillage a git repo found in an accessible web root☆60Updated 13 years ago
- ☆159Updated 6 years ago
- This is sample code to demonstrate how one can use SQL Injection vulnerability to download local file from server in specific condition. …☆44Updated 7 years ago
- ActionScript Proof of Concept to perform cross-domain reads☆45Updated 11 years ago