disclose / research-threats
Collection of legal threats against good faith Security Researchers; vulnerability disclosure gone wrong. A continuation of work started by @attritionorg
☆296Updated 3 months ago
Alternatives and similar repositories for research-threats
Users that are interested in research-threats are comparing it to the libraries listed below
Sorting:
- A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering☆210Updated 4 years ago
- Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki☆203Updated 6 months ago
- ☆77Updated 2 years ago
- One-stop TLS traffic inspection and manipulation using dynamic instrumentation☆243Updated 2 years ago
- CQ, a code security scanner☆100Updated 11 months ago
- Private key usage verification☆431Updated last month
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆123Updated 2 years ago
- Checks all maintainers of all NPM and Pypi packages for hijackable packages through domain re-registration☆296Updated this week
- An open source intelligence tool to crawl the graph of certificate Alternate Names☆350Updated last year
- Bash Proof-of-Concept (PoC) script to exploit SIGRed (CVE-2020-1350). Achieves Domain Admin on Domain Controllers running Windows Server …☆104Updated 4 years ago
- Open a DNS server that knows no records but records every request. Used for DNS exfiltration.☆68Updated 3 years ago
- The TLS-Scanner Module from TLS-Attacker☆274Updated last month
- An Open Letter to the OWASP Board☆106Updated last year
- Slide decks from my conference presentations☆363Updated last year
- Solitude is a privacy analysis tool that enables anyone to conduct their own privacy investigations. Whether a curious novice or a more a…☆372Updated 4 years ago
- A step by step workshop to exploit various vulnerabilities in Node.js and Java applications☆156Updated last year
- 🏴☠️ Bypass Same Origin Policy with DNS-rebinding to retrieve local server files 🏴☠️☆199Updated 6 years ago
- Trail of Bits Testing Handbook☆72Updated last month
- TLS-Anvil, a fully automated TLS testsuite for client and servers.☆92Updated last year
- scylla.sh db dumps and more☆135Updated 4 years ago
- Burp with Friends☆103Updated 2 years ago
- materials we hand out☆144Updated last month
- Proofs of Concept. Just fucking around.☆193Updated 2 years ago
- An extensively configurable tool providing a summary of the changes between two files or directories, ignoring all the fluff you don't ca…☆202Updated 2 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆352Updated 4 years ago
- List of the tools and usage☆233Updated 2 years ago
- A Passive SSH back-end and scanner.☆102Updated 2 months ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆139Updated 3 years ago
- A repository of previous info-sec presentations I've presented.☆161Updated 6 months ago
- This repo contains logstash of various honeypots☆174Updated 5 years ago