koenbuyens / oauth-2.0-security-cheat-sheetView external linksLinks
oauth security guidelines
☆230Jun 25, 2019Updated 6 years ago
Alternatives and similar repositories for oauth-2.0-security-cheat-sheet
Users that are interested in oauth-2.0-security-cheat-sheet are comparing it to the libraries listed below
Sorting:
- vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.☆325Mar 27, 2024Updated last year
- GraphQL automated security testing toolkit☆333Feb 20, 2024Updated last year
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆190Aug 11, 2022Updated 3 years ago
- Recon tool for URLs discovery☆12Jun 19, 2024Updated last year
- Accompanying material needed for the workshop☆11Jun 14, 2023Updated 2 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆175Oct 26, 2024Updated last year
- An Intentionally designed Vulnerable Android Application built in Kotlin.☆256Mar 2, 2022Updated 3 years ago
- 🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.☆427Feb 9, 2026Updated last week
- A curated list of awesome browser security learning material.☆149Nov 20, 2022Updated 3 years ago
- A cheatsheet for exploiting server-side SVG processors.☆790Jul 2, 2020Updated 5 years ago
- Everything about xss protection technology☆14Oct 22, 2019Updated 6 years ago
- Modular Kubernetes lab which provides an easy and streamlined way to deploy a test cluster with support for different components.☆53Oct 2, 2025Updated 4 months ago
- A very vulnerable implementation of a GraphQL API.☆61Nov 12, 2021Updated 4 years ago
- Check any website (or set of websites) for insecure security headers.☆255Jun 12, 2023Updated 2 years ago
- Python script to launch burp scans automatically☆33Jul 18, 2021Updated 4 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆32Dec 10, 2022Updated 3 years ago
- ☆24Jan 26, 2021Updated 5 years ago
- Awesome secure by default libraries to help you eliminate bug classes!☆699Dec 6, 2025Updated 2 months ago
- An invoice management application built on the MEAN stack with intentional vulnerabilities used to demonstrate insecure configurations an…☆16Sep 4, 2020Updated 5 years ago
- Burp Suite Extension useful to verify OAUTHv2 and OpenID security☆190Dec 3, 2024Updated last year
- Websec interview questions by tib3rius answered☆309Nov 13, 2023Updated 2 years ago
- Proof of concept code for Datadog Security Labs referenced exploits.☆449Updated this week
- This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage clou…☆2,804Sep 17, 2024Updated last year
- security.txt collection of most popular world-wide domains☆55Sep 25, 2023Updated 2 years ago
- 🦄🔒 Awesome list of secrets in environment variables 🖥️☆901Sep 21, 2022Updated 3 years ago
- Prototype Pollution and useful Script Gadgets☆1,581Jan 27, 2024Updated 2 years ago
- ☆227Dec 18, 2025Updated last month
- Recurrent Neural Network SubDomain Discovery Tool☆95Sep 20, 2022Updated 3 years ago
- [A]ndroid [A]pplication [P]entest [G]uide☆123Oct 10, 2019Updated 6 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability☆951Dec 31, 2021Updated 4 years ago
- A collection of simple tools and poc-builders☆39Jul 22, 2025Updated 6 months ago
- offensive notes & resources☆43Apr 7, 2025Updated 10 months ago
- Scans Slack for API tokens, credentials, passwords, and more using YARA rules☆40Feb 26, 2021Updated 4 years ago
- ☆1,201Sep 2, 2022Updated 3 years ago
- Prototype pollution scanner using headless chrome☆218Jul 27, 2022Updated 3 years ago
- AWSGoat : A Damn Vulnerable AWS Infrastructure☆1,967May 20, 2025Updated 8 months ago
- A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.☆109Mar 1, 2022Updated 3 years ago
- PoC for CVE-2025-48384☆20Jul 9, 2025Updated 7 months ago
- Repo to hold the markdown-ified metadata on AppSec tools that are automation-friendly☆12Jun 13, 2016Updated 9 years ago