doyensec / Unsafe-Unpacking
Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide
☆41Updated 5 months ago
Alternatives and similar repositories for Unsafe-Unpacking
Users that are interested in Unsafe-Unpacking are comparing it to the libraries listed below
Sorting:
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆12Updated last year
- Proof of Concepts for unsafe deserialization in Ruby☆16Updated 7 months ago
- Simple WebSocket fuzzer☆32Updated last year
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆32Updated 2 months ago
- ☆32Updated 2 years ago
- ☆18Updated 2 months ago
- ☆23Updated 3 months ago
- Utility for creating ZipSlip archives☆72Updated 2 years ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆47Updated last year
- This repository offers insights and a proof-of-concept tool to exploit two significant deserialization vulnerabilities in Inductive Autom…☆44Updated last year
- ☆14Updated 5 months ago
- ☆26Updated last year
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆17Updated last year
- ☆34Updated last month
- A curated list of argument injection vectors☆41Updated 3 months ago
- A collection of my Semgrep rules☆49Updated last year
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆88Updated 6 months ago
- Updated version of the ProtoBurp Extension, with enhanced features and capabilities to encode and fuzz custom protobuf messages☆36Updated last year
- A collection of utilities for building extensions using Burp's Montoya API☆50Updated 10 months ago
- ☆31Updated 2 years ago
- A simple mutator engine which focuses on finding unknown classes of injection vulnerabilities☆67Updated last year
- An extension to use Semgrep inside Burp Suite.☆89Updated last year
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆26Updated last year
- Dependency Confusion Security Testing Tool☆47Updated 2 years ago
- some sploits☆17Updated 7 months ago
- a Ruby implementation of Java's ObjectInputStream and ObjectOutputStream.☆16Updated 2 years ago
- php7.4.26-internalog☆13Updated 2 years ago
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆21Updated 2 months ago
- A powerful AWS Cognito analysis and session hijacking toolkit designed for security researchers and penetration testers. CognitoHunter sp…☆20Updated 3 months ago
- ☆16Updated last year