oauth security guidelines
☆232Jun 25, 2019Updated 6 years ago
Alternatives and similar repositories for oauth-2.0-security-cheat-sheet
Users that are interested in oauth-2.0-security-cheat-sheet are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.☆330Mar 27, 2024Updated 2 years ago
- GraphQL automated security testing toolkit☆335Feb 20, 2024Updated 2 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆190Aug 11, 2022Updated 3 years ago
- An Intentionally designed Vulnerable Android Application built in Kotlin.☆257Mar 2, 2022Updated 4 years ago
- An invoice management application built on the MEAN stack with intentional vulnerabilities used to demonstrate insecure configurations an…☆16Sep 4, 2020Updated 5 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- 🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.☆428Jun 8, 2026Updated last week
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆178Oct 26, 2024Updated last year
- Awesome secure by default libraries to help you eliminate bug classes!☆708Dec 6, 2025Updated 6 months ago
- Everything about xss protection technology☆14Oct 22, 2019Updated 6 years ago
- Custom scripts for the PIPER Burp extensions.☆98Sep 24, 2023Updated 2 years ago
- Recon tool for URLs discovery☆12Jun 19, 2024Updated 2 years ago
- A collection of simple tools and poc-builders☆39May 28, 2026Updated 3 weeks ago
- Recurrent Neural Network SubDomain Discovery Tool☆95Sep 20, 2022Updated 3 years ago
- Python script to launch burp scans automatically☆32Jul 18, 2021Updated 4 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- security.txt collection of most popular world-wide domains☆56Sep 25, 2023Updated 2 years ago
- Modular Kubernetes lab which provides an easy and streamlined way to deploy a test cluster with support for different components.☆53Oct 2, 2025Updated 8 months ago
- Proof of concept code for Datadog Security Labs referenced exploits.☆448Updated this week
- Accompanying material needed for the workshop☆11Jun 14, 2023Updated 3 years ago
- A cheatsheet for exploiting server-side SVG processors.☆802Jul 2, 2020Updated 5 years ago
- 🦄🔒 Awesome list of secrets in environment variables 🖥️☆911Sep 21, 2022Updated 3 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆192Dec 3, 2024Updated last year
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆32Dec 10, 2022Updated 3 years ago
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,818Apr 6, 2026Updated 2 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- A curated list of awesome browser security learning material.☆153Nov 20, 2022Updated 3 years ago
- ☆24Jan 26, 2021Updated 5 years ago
- Websec interview questions by tib3rius answered☆309Nov 13, 2023Updated 2 years ago
- ☆244Jun 3, 2026Updated 2 weeks ago
- A very vulnerable implementation of a GraphQL API.☆62Nov 12, 2021Updated 4 years ago
- A simple script to check for insecurely exposed git repositories.☆12Mar 17, 2019Updated 7 years ago
- A custom built DNS bruteforcer with multi-threading, and handling of bad resolvers.☆56Apr 25, 2022Updated 4 years ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rules☆40Feb 26, 2021Updated 5 years ago
- Prototype Pollution and useful Script Gadgets☆1,634Jan 27, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- ☆1,201Sep 2, 2022Updated 3 years ago
- A collection of Turbo Intruder scripts.☆73Feb 1, 2025Updated last year
- Vulnerable app with examples showing how to not use secrets☆1,446Updated this week
- ☆438Jun 1, 2021Updated 5 years ago
- Filter and enrich a list of subdomains by level☆212Sep 25, 2023Updated 2 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆978Dec 31, 2021Updated 4 years ago
- ☆34Jun 23, 2021Updated 4 years ago