kaakaww / vuln-graphql-api
A very vulnerable implementation of a GraphQL API.
☆14Updated last month
Alternatives and similar repositories for vuln-graphql-api:
Users that are interested in vuln-graphql-api are comparing it to the libraries listed below
- A walkthrough of security controls for a serverless architecture via a demo application☆11Updated 2 years ago
- A very vulnerable implementation of a GraphQL API.☆57Updated 3 years ago
- Fetch the details of assets hosted on AWS.☆86Updated last year
- A colorful cross-platform python script to test misconfigurations of AWS S3 buckets both through authenticated and unauthenticated checks…☆39Updated 3 years ago
- Jekyll Files for cloudsecwiki.com☆50Updated 3 years ago
- OWASP Foundation Web Respository☆10Updated last year
- A vulnerability fuzzing tool written in bash, it contains the most commonly used tools to perform vulnerability scan☆79Updated 3 years ago
- ZAP Management Scripts☆21Updated last week
- Pull secrets from an AWS environment☆70Updated 4 years ago
- ☆13Updated 9 months ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?☆13Updated 4 months ago
- A small library to alter AWS API requests; Used for fuzzing research☆22Updated last year
- Determine privileges from cloud credentials via brute-force testing.☆66Updated 5 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- Fork of https://github.com/PortSwigger/param-miner for header smuggling research☆12Updated 3 years ago
- DEPRECATED, please use the new repository from OWASP: https://github.com/OWASP/raider☆138Updated 3 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 4 months ago
- code reviews to practice☆16Updated 3 years ago
- OWASP Foundation Web Respository☆34Updated 4 months ago
- WAF bypass PoC☆46Updated last year
- ☆22Updated 2 years ago
- ☆23Updated 11 months ago
- DustiLock is a tool to find which of your dependencies is susceptible to a Dependency Confusion attack.☆35Updated 3 years ago
- AWS IAM resources search tool☆20Updated 3 years ago
- GitHub action to run Threagile, the agile threat modeling toolkit, on a repo's threagile.yaml file☆13Updated 8 months ago
- This Repository contains the stable beta preview of the next major secureCodeBox (SCB) release v2.0.0.☆24Updated 4 years ago
- javaspringvulny - a Spring Boot web application built wrong on purpose☆19Updated this week
- ☆14Updated 2 years ago
- ☆78Updated 9 months ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago