cweb / unicode-hax
A library to assist in security-testing Unicode enabled applications during fuzzing, XSS, SQLi, etc.
☆42Updated 7 years ago
Alternatives and similar repositories for unicode-hax:
Users that are interested in unicode-hax are comparing it to the libraries listed below
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- ☆70Updated 7 years ago
- Tests for different parsers from Ruby, Python, .NET, PHP, Perl, Java☆55Updated 8 years ago
- Demo server for testing Java deserialization payloads☆15Updated 8 years ago
- Writeup of CVE-2017-1002101 with sample "exploit"/escape☆35Updated 7 years ago
- A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities☆60Updated 8 years ago
- Burp extension to quickly and easily develop Python complex exploits based on Burp proxy requests.☆33Updated 9 years ago
- An interactive OOB XXE data exfiltration tool☆90Updated 7 years ago
- HTML5 WebSocket message fuzzer☆145Updated 6 years ago
- Burp extension to help developers replicate findings from pen tests☆70Updated 9 months ago
- Dirbuster plugin for Burp Suite☆70Updated 8 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆34Updated 8 years ago
- This test suite contains over 40 different test cases that have proven to work with different mobile browsers in my research or testing S…☆30Updated 5 years ago
- Exploit insecure crossdomain.xml files.☆26Updated 8 years ago
- Burp Suite extension to generate Intruder payloads using Radamsa☆89Updated 7 years ago
- Extension adds a new tab in Burp Suite called Extractor☆42Updated 6 years ago
- XXE OOB Exploitation Toolset for Automation☆63Updated 11 years ago
- Highlight Burp proxy requests made by different browsers☆30Updated 7 years ago
- A Java serializer in JavaScript☆81Updated 6 years ago
- A tool for detecting XML External Entity (XXE) vulnerabilities in Java applications☆72Updated 10 years ago
- OAuth plugin for Burp Suite Extender☆42Updated 6 years ago
- Improved decoder for Burp Suite☆138Updated 3 years ago
- HTTPWookiee is an HTTP server and proxy stress tool (respect of RFC, HTTP Smuggling issues, etc). If you run an HTTP server project conta…☆50Updated 7 years ago
- BlindRef serves as the basis for an automated Blind-Based XXE Exploitation Framework☆26Updated 8 years ago
- Image size issues plugin for Burp Suite☆94Updated 6 years ago
- A front-end JavaScript toolkit for creating DNS rebinding attacks.☆45Updated 6 years ago
- Penetration Testing Tools Developed by AppSec Consulting.☆48Updated 6 years ago
- Burp Suite plugin created for using Collaborator tool during manual testing in a comfortable way!☆103Updated 6 years ago
- Materials related to the 2017 BSides Las Vegas presentation☆52Updated 4 years ago
- ☆24Updated 9 years ago