google / csp-evaluator
☆346Updated last week
Alternatives and similar repositories for csp-evaluator:
Users that are interested in csp-evaluator are comparing it to the libraries listed below
- WebAppSec Content Security Policy☆215Updated 3 weeks ago
- Custom ESLint rule to disallows unsafe innerHTML, outerHTML, insertAdjacentHTML and alike☆234Updated 3 months ago
- The request.bin of DNS request☆233Updated 6 years ago
- Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.☆202Updated 8 months ago
- Content released at NorthSec 2018 for my talk on prototype pollution☆521Updated 9 months ago
- A collection of browser-based side channel attack vectors.☆746Updated 11 months ago
- A browser API to prevent DOM-Based Cross Site Scripting in modern web applications.☆615Updated last month
- research☆151Updated 11 months ago
- ☆143Updated 2 years ago
- ☆534Updated last year
- XS-Leaks Wiki☆156Updated last month
- DOM XSS scanner for Single Page Applications☆402Updated 7 months ago
- Simple DNS Rebinding Service☆646Updated 5 years ago
- Cure53 Browser Security White Paper☆288Updated 7 years ago
- Automatically exported from code.google.com/p/domxsswiki☆526Updated 6 years ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆321Updated 3 years ago
- Companion labs to "An Exploration of JSON Interoperability Vulnerabilities"☆201Updated last year
- ☆675Updated 2 years ago
- ☆188Updated 2 weeks ago
- Certificate Transparency log monitor☆359Updated 2 months ago
- HTTP.ninja☆149Updated last year
- SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.☆457Updated 7 years ago
- HTTPWookiee is an HTTP server and proxy stress tool (respect of RFC, HTTP Smuggling issues, etc). If you run an HTTP server project conta…☆50Updated 7 years ago
- Content hijacking proof-of-concept using Flash, PDF and Silverlight☆379Updated 5 years ago
- A tool to perform Sequential Import Chaining☆259Updated 5 years ago
- a javascript static security analysis tool☆589Updated 9 years ago
- This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard cer…☆285Updated last month
- TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.☆310Updated last year
- Burp extension to detect alias traversal via NGINX misconfiguration at scale.☆258Updated 3 years ago
- GitHub Satellite 2020 workshops on finding security vulnerabilities with CodeQL for Java/JavaScript.☆209Updated 5 months ago