dxa4481 / CORSLinks
JSON API's Are Automatically Protected Against CSRF, And Google Almost Took It Away.
☆34Updated 8 years ago
Alternatives and similar repositories for CORS
Users that are interested in CORS are comparing it to the libraries listed below
Sorting:
- An example of obtaining RCE via Redis and CSRF☆76Updated 8 years ago
- A tiny chrome extension to record and replay your web application proof-of-concepts.☆20Updated 8 years ago
- Framework for Automated Security Testing that is Scaleable and Asynchronous built on Microservices☆18Updated 8 years ago
- Exploit insecure crossdomain.xml files.☆26Updated 8 years ago
- Jaqen - Simple DNS rebinding☆72Updated 7 years ago
- This is sample code to demonstrate how one can use SQL Injection vulnerability to download local file from server in specific condition. …☆44Updated 8 years ago
- CSV injection Vulnerable Script.☆29Updated 8 years ago
- WebBorer is a directory-enumeration tool written in Go.☆44Updated 2 years ago
- An implementation of the hashcat rules engine in javascript☆48Updated 7 years ago
- Cronbased Dirty Cow Exploit☆31Updated 8 years ago
- Write Up I write for different CTFs☆12Updated 7 years ago
- A Firefox extension and WebSocket handler that checks S3/Google/Azure buckets while your browse.☆37Updated 5 years ago
- Use burp's JS static code analysis on code from your local system.☆42Updated 8 years ago
- ☆32Updated 9 years ago
- REST/JSON interface to Burp Suite☆33Updated 4 years ago
- A deliberately vulnerable modern day app with lots of DOM related bugs☆35Updated 6 years ago
- ☆28Updated 9 years ago
- A Platform for Testing Secure Coding/Config☆18Updated 6 years ago
- Testing/collecting some container breakouts☆94Updated 5 years ago
- A front-end JavaScript toolkit for creating DNS rebinding attacks.☆45Updated 7 years ago
- ☆60Updated 7 years ago
- Demo server for testing Java deserialization payloads☆15Updated 8 years ago
- Very crude and poorly written HTTP(s) and SMTP bin☆93Updated 4 years ago
- ☆12Updated 8 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆56Updated 3 years ago
- Scan for and exploit Consul agents☆40Updated 6 years ago
- Materials related to the 2017 BSides Las Vegas presentation☆52Updated 4 years ago
- Simple, hand-picked list of fuzz strings☆33Updated 8 years ago
- XSS in pastebin.com and reddit.com via unsanitized markdown output☆87Updated 7 years ago
- PLASMA PULSAR☆69Updated 8 years ago