fuzz-security / MobileApp-Pentest-Cheatsheet
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
☆71Updated 4 years ago
Alternatives and similar repositories for MobileApp-Pentest-Cheatsheet:
Users that are interested in MobileApp-Pentest-Cheatsheet are comparing it to the libraries listed below
- Slides and other material from various conference presentations.☆44Updated last month
- Intentionally vulnerable webview implementions in Android☆56Updated 3 years ago
- Identifies vulnerabilities in network_security_config.xml, AndroidManifest.xml and if Firebase URL are accessible publicly☆49Updated 2 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆109Updated 3 years ago
- Burp Bounty profiles☆82Updated 3 years ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆27Updated 4 years ago
- ☆97Updated 3 years ago
- This is a burp plugin that extracts keywords from response using regexes and test for reflected XSS on the target scope.☆76Updated 4 years ago
- Detects request smuggling via HTTP/2 downgrades.☆92Updated 2 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- A Bash wrapper for radamsa that can be used to fuzz exported activities and deep links.☆51Updated 3 years ago
- URL Screenshot Utility☆27Updated last year
- Static and dynamic Android application security analysis☆72Updated 11 months ago
- A more useful CSRF PoC generator on Burp Suite☆87Updated 2 years ago
- Fuzzing script for redirect URL validator☆52Updated 5 years ago
- This repository explain how to write frida hook scripts and analysis written hooks.☆82Updated last year
- This repository contains all the examples related to a series of tutorials that demonstrate how to use the new Montoya API of Burp Suite …☆41Updated 5 months ago
- A Web-UI for subdomain enumeration (subfinder)☆54Updated 4 years ago
- Compiled dataset of Java deserialization CVEs☆61Updated 4 years ago
- Script to test open Akamai ARL vulnerability.☆71Updated 3 years ago
- Authenticated SSRF in Grafana☆82Updated 10 months ago
- ☆44Updated 3 years ago
- Expand urls into one url for each path depth☆34Updated 4 years ago
- ☆55Updated 2 years ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆56Updated last year
- ☆46Updated 4 years ago
- An actively maintained, Self curated notes related to android application security for security professionals, bugbounty hunters, pentes…☆214Updated 3 years ago
- ☆33Updated 2 years ago
- ☆165Updated 3 years ago