detectify / vulnerable-nginx
An intentionally vulnerable NGINX setup
☆232Updated 4 years ago
Alternatives and similar repositories for vulnerable-nginx:
Users that are interested in vulnerable-nginx are comparing it to the libraries listed below
- ☆528Updated last year
- Content-Type Research☆572Updated 11 months ago
- ☆168Updated 3 years ago
- Client Side Prototype Pollution Scanner☆510Updated 2 years ago
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆347Updated 5 months ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆832Updated 3 years ago
- This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests a…☆321Updated 3 years ago
- List of periodically validated public DNS resolvers☆229Updated this week
- NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.☆369Updated 3 years ago
- Automated learning of regexes for DNS discovery☆362Updated last year
- Tool for catching and logging different types of requests.☆219Updated 4 years ago
- automated web assets enumeration & scanning [DEPRECATED]☆286Updated last year
- Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease appli…☆230Updated last month
- Exploits targeting Symfony☆197Updated 4 months ago
- HTTP Request Smuggling over HTTP/2 Cleartext (h2c)☆679Updated 2 years ago
- A DNS Bruteforcing Wordlist Generator☆350Updated last year
- This repo contains all the injections mentioned in my talk and enumerators.☆121Updated last year
- Tools to assess the DNS security of web applications☆127Updated 2 years ago
- PNG IDAT chunks XSS payload generator☆180Updated 2 years ago
- This repository contains all the XSS cheatsheet data to allow contributions from the community.☆415Updated 2 months ago
- DOM XSS scanner for Single Page Applications☆400Updated 6 months ago
- DNS rebinding toolkit☆251Updated last year
- Simple websites vulnerable to Server Side Template Injections(SSTI)☆383Updated last year
- This tool is for letting you know how strong your disable_functions is and how you can bypass that.☆120Updated 5 years ago
- Scrape domain names from SSL certificates of arbitrary hosts☆629Updated 9 months ago
- Gotator is a tool to generate DNS wordlists through permutations.☆465Updated 2 years ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆346Updated 2 years ago
- Proof of concept code for Datadog Security Labs referenced exploits.☆420Updated last year
- Tools to assess DNS security.☆151Updated 10 months ago
- ☆158Updated 3 years ago