kelbyludwig / saml-attack-surface
☆29Updated 8 years ago
Alternatives and similar repositories for saml-attack-surface
Users that are interested in saml-attack-surface are comparing it to the libraries listed below
Sorting:
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆33Updated 6 years ago
- A Burp Suite content discovery plugin that add the smart into the Buster!☆31Updated 7 years ago
- Slides of the talk on Injection attacks in apps with NoSQL Backends, given at null OWASP Bangalore monthly meet on 27th April 2019☆22Updated 6 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated 2 years ago
- Terraform configuration to build a Burp Private Collaborator Server☆29Updated 6 years ago
- This burpsuite extender provides a solution on testing Enterprise applications that involve security Authorization tokens into every HTTP…☆46Updated 6 years ago
- A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.☆26Updated 6 years ago
- ☆12Updated 7 years ago
- Simple XXE test suite generated specifically for SAML interfaces☆22Updated 6 years ago
- Terraform configuration to build a Burp Private Collaborator Server☆25Updated 7 years ago
- Clickjacking PoC Generator☆35Updated 4 years ago
- Proof-of-concept CORS exploitation tool.☆35Updated 5 years ago
- This is a Burp extension for adding additional payloads to active scanner that require out-of-band validation. Works great with XSSHunter☆20Updated 8 years ago
- Kubernetes Scanner☆40Updated 3 years ago
- ☆38Updated 4 years ago
- OAuth Security Cheatsheet☆40Updated 11 years ago
- My IDA scripts, tips and testing techniques for Thick Client applications.☆17Updated 10 years ago
- List of special metadata IPs used in cloud services☆11Updated 5 years ago
- Parse X509 certificates to get the (sub)domains in it.☆28Updated 6 years ago
- Extensive code infrastructure for finding unintended information leaks in files, git repositories and much more.☆28Updated 2 years ago
- String or worldlist encoder for use in fuzzing or web application testing☆19Updated 5 years ago
- PHP tool to test XSS☆22Updated 5 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆14Updated 3 years ago
- Scripts that I've written that others may find useful☆14Updated 2 years ago
- A bash script that fetches and maintains thousands of DNS resolvers☆65Updated 4 years ago
- ☆32Updated 5 years ago
- Burp Suite extension to help make Graphql request more readable☆31Updated 7 years ago
- Collection of different exploitation scenarios of JWT.☆21Updated 3 years ago
- retrive metadata endpoint data with these one liners.☆38Updated 4 years ago
- Simple trick to increase readability of exceptions raised by Burp extensions written in Python☆43Updated 8 years ago