iixlabs / websec-training
A collection of vulnerable web applications in Node.js to practice security fundamentals
☆13Updated 8 years ago
Alternatives and similar repositories for websec-training:
Users that are interested in websec-training are comparing it to the libraries listed below
- MoneyX is an intentionally vulnerable JSP application used for training developers in application security concepts.☆31Updated 8 years ago
- Local privilege escalation scripts and tools☆16Updated 8 years ago
- A tool to extract database data from a blind SQL injection vulnerability.☆31Updated 9 years ago
- REST/JSON interface to Burp Suite☆33Updated 4 years ago
- Faraday Workspaces for Bug Bounties☆20Updated 9 years ago
- Advanced HTTP fingerprinting PoC☆44Updated 7 years ago
- Tools for MITMing Yahoo! Mail with a Wifi Pineapple Mark V and Flash☆28Updated 8 years ago
- Python Implementation of a .NET Padding Oracle Assessment Tool☆30Updated 9 years ago
- Cross Distribution Exploit Testing☆27Updated 9 years ago
- CSV injection Vulnerable Script.☆29Updated 7 years ago
- Flash crossdomain policy security checker☆25Updated 9 years ago
- A Burp Suite extension that starts scanning on requests it sees, and dumps results on standard output☆20Updated 8 years ago
- Working Rsh Client With Bind/Reverse Shell☆20Updated 9 years ago
- ☆27Updated 7 years ago
- Simple python script to detect meterpreter running in memory (hopefully)☆9Updated 10 years ago
- Capture the flag - security challenges☆13Updated 8 years ago
- CHEF cookbook for automating provisioning of CTF competition and wargame challenge platforms☆12Updated 9 years ago
- DNS Enumeration and Reconnaissance Tool☆37Updated 9 years ago
- A tiny chrome extension to record and replay your web application proof-of-concepts.☆20Updated 8 years ago
- Python SDK to access the vulnerability database☆22Updated 5 years ago
- js-beautifier extension for Burp Suite☆30Updated 11 years ago
- An automated Python + Ruby based XXE Exploiter (GUI + CLI)☆20Updated 8 years ago
- Framework for Automated Security Testing that is Scaleable and Asynchronous built on Microservices☆18Updated 8 years ago
- Websocket based egress tester☆20Updated 8 years ago
- ParrotNG is a tool capable of identifying Adobe Flex applications (SWF) vulnerable to CVE-2011-2461☆47Updated 9 years ago
- A ready to deploy docker container for a fresh sandbox for on-the-fly malware analysis☆43Updated 7 years ago
- Network Scanner for OpenSSL Memory Leak (CVE-2014-0160)☆11Updated 9 years ago
- ☆24Updated 10 years ago
- sniff/log database traffic or actively execute arbitrary queries via TCP injection☆43Updated 8 years ago
- A security write-up about the Paypal API & data leakage☆24Updated 8 years ago