lauritzh / auth-request-analyserLinks
This Chromium extensions aims at supporting the analysis of single sign-on implementations, by offering semi-automated analysis and attack capabilities for OAuth 2.0 and OpenID Connect 1.0 Authorization/Authentication Requests.
☆29Updated 2 years ago
Alternatives and similar repositories for auth-request-analyser
Users that are interested in auth-request-analyser are comparing it to the libraries listed below
Sorting:
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆36Updated 11 months ago
- A collection of utilities for building extensions using Burp's Montoya API☆52Updated 3 months ago
- Dependency Confusion Security Testing Tool☆51Updated 3 years ago
- Make better use of the embedded browser that comes by default with Burp☆44Updated 2 years ago
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Updated last year
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆52Updated last year
- An extension to use Semgrep inside Burp Suite.☆89Updated 8 months ago
- Simple PoC for demonstrating Race Conditions on Websockets☆55Updated 2 years ago
- A powerful AWS Cognito analysis and session hijacking toolkit designed for security researchers and penetration testers. CognitoHunter sp…☆21Updated last year
- ☆92Updated 2 months ago
- ☆42Updated 2 months ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Updated 3 years ago
- ☆106Updated 3 years ago
- A set of open-source community scripts☆65Updated last year
- Utility for creating ZipSlip archives☆81Updated 3 years ago
- My talks...☆25Updated 11 months ago
- Unicode characters that will translate a single character to multiple characters in domain names or TLD's☆50Updated last year
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 3 years ago
- Burp extension to check and exploit the IIS Tilde Enumeration/IIS 8.3 Short Filename Disclosure vulnerability☆61Updated 2 years ago
- Burp Extension to add additional functionality for pentesting websocket based applications☆103Updated 5 months ago
- ☆34Updated 3 years ago
- Demo of various ways to exploit post based reflected XSS☆18Updated 2 years ago
- A GraphQL enumeration and extraction tool☆134Updated 3 years ago
- ☆29Updated 3 years ago
- Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.☆68Updated last year
- Mine URLs from Browser's Heap Snapshot for fun and profit☆64Updated 2 years ago
- A wrapper around grep, to help you grep for things! - Improved version of gf by @tomnomnom.☆62Updated 2 years ago
- ☆16Updated 2 months ago
- Let's check if your target is vulnerable for client side prototype pollution.☆65Updated 2 years ago
- Monitoring the Cloud Landscape☆92Updated last week