dxa4481 / CORS
JSON API's Are Automatically Protected Against CSRF, And Google Almost Took It Away.
☆35Updated 7 years ago
Alternatives and similar repositories for CORS:
Users that are interested in CORS are comparing it to the libraries listed below
- ☆25Updated 7 years ago
- Wax is a mediocre fuzzer I'm prototyping to test some ideas and get rid of others.☆18Updated 6 years ago
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- Jaqen - Simple DNS rebinding☆73Updated 7 years ago
- A centralized location for all presentations I've given at various conferences☆26Updated 7 years ago
- Social Engineering Abusing Google App Scripts☆24Updated 8 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆36Updated 5 years ago
- Framework for Automated Security Testing that is Scaleable and Asynchronous built on Microservices☆18Updated 8 years ago
- PoC for an adaptive parallelised DNS prober☆44Updated 7 years ago
- Exploit insecure crossdomain.xml files.☆26Updated 7 years ago
- A tiny chrome extension to record and replay your web application proof-of-concepts.☆20Updated 8 years ago
- Dynamic DNS Update Bruteforce Tool☆29Updated 8 years ago
- Scans crossdomain.xml policies for expired domain names.☆25Updated 9 years ago
- A Firefox extension and WebSocket handler that checks S3/Google/Azure buckets while your browse.☆37Updated 4 years ago
- WebBorer is a directory-enumeration tool written in Go.☆44Updated 2 years ago
- This is sample code to demonstrate how one can use SQL Injection vulnerability to download local file from server in specific condition. …☆44Updated 8 years ago
- OAuth Security Cheatsheet☆39Updated 10 years ago
- CSV injection Vulnerable Script.☆29Updated 7 years ago
- DNS Enumeration and Reconnaissance Tool☆37Updated 9 years ago
- Very crude and poorly written HTTP(s) and SMTP bin☆93Updated 4 years ago
- A Scaleable and Asynchronous Framework for Testing Tools built on Kubernetes☆35Updated 7 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆56Updated 3 years ago
- ParrotNG is a tool capable of identifying Adobe Flex applications (SWF) vulnerable to CVE-2011-2461☆48Updated 10 years ago
- Websocket based egress tester☆20Updated 8 years ago
- A Burp Extender plugin, that will deserialized java objects and encode them in XML using the Xtream library.☆25Updated 9 years ago
- A regular expression fuzzer.☆43Updated 7 years ago
- CTF website frontend for SecGen☆21Updated 7 years ago
- tundeep☆42Updated 5 years ago
- Run DependencyCheck Against Your Orgs GitHub Repos.☆14Updated 7 years ago
- Because I can't find scripts to do this anywhere else...☆25Updated 8 years ago