githubsatelliteworkshops / codeql
GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.
☆208Updated last month
Related projects ⓘ
Alternatives and complementary repositories for codeql
- When MVC magic turns black☆286Updated 4 years ago
- My CodeQL queries collection☆94Updated last year
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆344Updated 2 years ago
- [Deprecated] GitHub's Field Team's CodeQL Custom Queries, Suites, and Configurations. See GitHubSecurityLab/CodeQL-Community-Packs instea…☆80Updated 6 months ago
- A static byte code analyzer for Java deserialization gadget research☆241Updated 7 years ago
- Collection of community-driven CodeQL query, library and extension packs☆74Updated last week
- Prepackaged and precompiled github codeql container for rapid analysis, deployment and development.☆109Updated 11 months ago
- Personal CodeQL queries☆58Updated last week
- An example repository that demonstrates how the build custom CodeQL bundles that include query customizations through the `Customizations…☆25Updated 2 years ago
- Compiled dataset of Java deserialization CVEs☆60Updated 4 years ago
- GreHack 2021 CodeQL for Java workshop☆75Updated 3 years ago
- Grammar-based HTTP/1 fuzzer with mutation ability☆243Updated 3 weeks ago
- A Node.js vulnerability finding tool.☆95Updated 4 years ago
- ☆78Updated 3 years ago
- ☆175Updated 2 weeks ago
- A vulnerable application exposing Spring Boot Actuators☆122Updated 5 years ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆42Updated 2 years ago
- ☆70Updated 2 years ago
- Slides/Demos from the BSides Munich 2019 talk "Attacking Java RMI in 2019"☆101Updated 5 years ago
- ☆58Updated last year
- Fuzzing script for redirect URL validator☆48Updated 4 years ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- A proof-of-concept tool for detection and exploitation Object Injection Vulnerabilities in .NET applications☆62Updated 3 years ago
- Silent Spring: Prototype Pollution Leads to Remote Code Execution in Node.js☆56Updated 10 months ago
- CodeQL workshops for GitHub Universe☆91Updated 2 years ago
- Workshop on Template Injection (6 exercises) covering Twig, Jinja2, Tornado, Velocity and Freemaker engines.☆121Updated last year
- Binary rewriting approach with fork server support to fuzz Java applications with afl-fuzz.☆88Updated 6 years ago
- A variant analysis and visualisation tool that scans codebases for similar vulnerabilities☆69Updated 2 years ago
- Finding Java gadget chains with CodeQL☆159Updated 3 months ago
- ☆107Updated 2 years ago