indutny / heartbleed
Extracting server private key using Heartbleed OpenSSL vulnerability.
☆393Updated 9 years ago
Related projects ⓘ
Alternatives and complementary repositories for heartbleed
- An example of obtaining RCE via Redis and CSRF☆77Updated 8 years ago
- DNS rebinding is powerful: how to steal WiFi passwords by just tricking a victim into visiting a website, thanks to that fancy Bang & Olu…☆81Updated 5 years ago
- ☆74Updated 11 years ago
- XSS exploitation tool - access victims through HTTP proxy☆158Updated 10 years ago
- The databases, API's and managers behind https://websecweekly.org☆51Updated 9 years ago
- A dashboard for interesting DOM tricks/techniques.☆36Updated 3 years ago
- PoC for getting remote HTTP Server date using gzip compressed HTTP Response☆56Updated 8 years ago
- Wolves Among the Sheep☆147Updated last year
- Static analysis tool for javascript code based. Scanjs uses Esprima to convert sources to AST, then walks AST looking for patterns.☆54Updated 10 years ago
- burpbuddy exposes Burp Suites's extender API over the network through various mediums, with the goal of enabling development in any langu…☆156Updated 5 years ago
- Tainted PhantomJS☆53Updated 9 years ago
- [DEPRECATED] Static analysis tool for javascript code.☆429Updated 3 years ago
- Time Trial - A tool for performing feasibility analyses of timing attacks☆83Updated 10 years ago
- Exposing and documenting v8 runtime functions.☆28Updated 10 years ago
- Fuzzing web services in style with nodejs☆11Updated 5 years ago
- Test Suite and exemplary extensions of the "Attacking Browser Extensions" master's thesis☆28Updated 8 years ago
- Probably one of the smallest SSL MITM proxies you can make☆182Updated 9 years ago
- Deprecated please use https://github.com/Netflix/sleepy-puppy☆94Updated 6 years ago
- An experimental implementation of a bot client which interprets commands through Twitter, thus requiring no hosting of servers from the c…☆43Updated 9 years ago
- Understanding weaknesses within Internet Explorer's Isolated Heap and MemoryProtection☆90Updated 9 years ago
- Simple test for the May 2016 OpenSSL padding oracle (CVE-2016-2107)☆186Updated 5 years ago
- Proof-of-concept exploit code for CVE-2016-5696☆70Updated 8 years ago
- A tool for manipulating SWF files, leveraging zlib to craft alphanumeric-only valid SWF files in order to allow CSRF with SOP bypass than…☆110Updated 7 months ago
- Recovery of Plaintext iMessage Data Without Breaking Crypto☆106Updated 8 years ago
- A regular expression for most valid domains (including the latest TLDs)☆39Updated 9 years ago
- A regex based source code scanner.☆128Updated 7 years ago