The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2.0 Service Providers, also supporting SCIM protocol.
☆64Jul 23, 2026Updated last month
Alternatives and similar repositories for maSSO
Users that are interested in maSSO are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An extension to find callback endpoints in the background while searching the Web☆47Mar 26, 2026Updated 4 months ago
- Blogpost series showcasing interesting cloud - web app security bugs☆76Jul 20, 2026Updated last month
- Detect the cloud / hosting provider of a given host. Fast, static & offline☆16Updated this week
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆69Mar 2, 2026Updated 5 months ago
- Burp plugin for jxscout☆25May 12, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆10Aug 14, 2026Updated last week
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 7 months ago
- An implementation of infrastructure-as-code scanning using dynamic tooling.☆56Jan 18, 2022Updated 4 years ago
- 0xJS is an AI-powered JavaScript Security Tool☆66Apr 16, 2026Updated 4 months ago
- Advanced test for proxy & waf☆14Feb 10, 2026Updated 6 months ago
- My Main App Hacking CheckList☆34Jun 20, 2026Updated 2 months ago
- ☆47Sep 21, 2025Updated 11 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆27Jun 16, 2026Updated 2 months ago
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆24Jan 19, 2026Updated 7 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- ☆26Jun 6, 2026Updated 2 months ago
- Library of Exploiting Last Frame Synchronization (also know as Single Packet Attack) on HTTP/3 - Manipulated version of quic-go lib☆20Jun 23, 2026Updated 2 months ago
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- ☆51Aug 2, 2025Updated last year
- EncryptInterceptor fail-open bypass in Apache Tomcat Tribes clustering leading to unauthenticated RCE via Java deserialization.☆70May 11, 2026Updated 3 months ago
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆24Updated this week
- this is everything☆44Apr 7, 2026Updated 4 months ago
- Regex patterns for manual application source code review☆34Dec 14, 2020Updated 5 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A python script to automatically dump files and source code of a Symfony server in debug mode.☆13Feb 11, 2025Updated last year
- Exploit for CVE-2024-0402 in Gitlab☆15Mar 18, 2025Updated last year
- Burp Suite extension that extends Burp to support storing and reusing variables in requests☆30Feb 10, 2026Updated 6 months ago
- A tool to extract and dump files of mercurial SCM exposed on a web server.☆13Jan 31, 2025Updated last year
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 3 months ago
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆124Updated this week
- Hard fork of mcguinness/saml-idp; a local SAML Identity Provider (IdP) library to test SAML 2.0 Service Providers (SPs).☆11Oct 8, 2024Updated last year
- Dependency Confusion Security Testing Tool☆50Jul 21, 2022Updated 4 years ago
- PoC's and Slides from 'Gophers, whales and.. clouds? Oh my!' BSides Wellington presentation by Glenn 'devalias' Grant☆17Mar 3, 2018Updated 8 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆46May 12, 2025Updated last year
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 5 months ago
- ☆57Jun 28, 2026Updated last month
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 2 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆33Updated this week
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 4 months ago