The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2.0 Service Providers, also supporting SCIM protocol.
☆67Sep 18, 2026Updated 2 weeks ago
Alternatives and similar repositories for maSSO
Users that are interested in maSSO are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An extension to find callback endpoints in the background while searching the Web☆48Mar 26, 2026Updated 6 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆76Jul 20, 2026Updated 2 months ago
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 7 months ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- Advanced test for proxy & waf☆13Feb 10, 2026Updated 7 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆48Sep 21, 2025Updated last year
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆14Aug 14, 2026Updated last month
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆188Updated this week
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 3 months ago
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 9 months ago
- ☆27Jun 6, 2026Updated 3 months ago
- Library of Exploiting Last Frame Synchronization (also know as Single Packet Attack) on HTTP/3 - Manipulated version of quic-go lib☆20Sep 10, 2026Updated 3 weeks ago
- Regex patterns for manual application source code review☆35Dec 14, 2020Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆51Aug 2, 2025Updated last year
- A python script to automatically dump files and source code of a Symfony server in debug mode.☆13Sep 8, 2026Updated 3 weeks ago
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆69May 11, 2026Updated 4 months ago
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆13Jan 31, 2025Updated last year
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆29Jun 16, 2026Updated 3 months ago
- Hard fork of mcguinness/saml-idp; a local SAML Identity Provider (IdP) library to test SAML 2.0 Service Providers (SPs).☆11Oct 8, 2024Updated last year
- Dependency Confusion Security Testing Tool☆51Jul 21, 2022Updated 4 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆46May 12, 2025Updated last year
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated 2 years ago
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 6 months ago
- The action integrates Electronegativity, a tool to identify misconfigurations and security anti-patterns in Electron applications, into G…☆15Apr 15, 2023Updated 3 years ago
- ☆40Aug 2, 2024Updated 2 years ago
- ☆11Jan 8, 2023Updated 3 years ago
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆25Jan 19, 2026Updated 8 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Updated this week
- A script to factorize integers with sagemath and factordb.☆11Feb 11, 2025Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- A Web Platform API proposal for Blob URL☆12Feb 24, 2023Updated 3 years ago
- this is everything☆47Apr 7, 2026Updated 5 months ago
- Easy discovery of assets☆13Jun 22, 2022Updated 4 years ago
- ☆21Jun 26, 2024Updated 2 years ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆131Updated this week
- Rust-based password mutator for brute force attacks☆13Mar 21, 2025Updated last year
- A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during test…☆62Jun 28, 2026Updated 3 months ago