detectify / vulnerable-nginxLinks
An intentionally vulnerable NGINX setup
☆241Updated 4 years ago
Alternatives and similar repositories for vulnerable-nginx
Users that are interested in vulnerable-nginx are comparing it to the libraries listed below
Sorting:
- ☆553Updated 5 months ago
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆374Updated last year
- Client Side Prototype Pollution Scanner☆518Updated 2 years ago
- Web dashboard for Interactsh client☆225Updated 3 months ago
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆387Updated 3 years ago
- Content-Type Research☆630Updated 2 months ago
- Exploits targeting Symfony☆207Updated 11 months ago
- ☆182Updated 2 months ago
- This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests a…☆338Updated 4 years ago
- navgix is a multi-threaded golang tool that will check for nginx alias traversal vulnerabilities☆72Updated 2 years ago
- HTTP Request Smuggling over HTTP/2 Cleartext (h2c)☆750Updated 3 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆175Updated 10 months ago
- Automated learning of regexes for DNS discovery☆372Updated 2 years ago
- Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"☆209Updated 2 years ago
- This repo contains all the injections mentioned in my talk and enumerators.☆130Updated last year
- One stop place for exploiting Jira instances in your proximity☆190Updated last year
- Burpsuite plugin for Interact.sh☆227Updated last year
- DNS rebinding toolkit☆253Updated 2 years ago
- Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.☆263Updated last year
- A proof-of-concept WordPress plugin fuzzer☆194Updated last year
- XS-Leaks Wiki☆169Updated 3 months ago
- Scrape domain names from SSL certificates of arbitrary hosts☆658Updated last year
- Tools to assess the DNS security of web applications☆128Updated 2 years ago
- Awesome information for WebSockets security research☆275Updated 3 years ago
- Predict Mongo ObjectIds☆145Updated 7 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆890Updated 3 years ago
- Security Testing Scripts for JWT☆316Updated 3 years ago
- 🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.☆424Updated 3 weeks ago
- Http request smuggling vulnerability scanner☆226Updated 3 years ago
- List of periodically validated public DNS resolvers☆234Updated this week