layro01 / node-api-goat
A simple Node.js Express REST app with some OWASP vulnerabilities.
☆16Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for node-api-goat
- This is vulnerable microservice written in many language to demonstrating OWASP API Top Security Risk (under development)☆42Updated last year
- A very vulnerable implementation of a GraphQL API.☆57Updated 3 years ago
- ☆71Updated last year
- Target practice for ffuf☆59Updated 3 years ago
- Intentionaly very vulnerable API with bonus bad coding practices☆40Updated 9 months ago
- A simple place to learn XSS☆30Updated 3 years ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- 🐑 Websheep is an app based on a willingly vulnerable ReSTful APIs.☆50Updated 7 months ago
- Regex patterns for manual application source code review☆25Updated 3 years ago
- Quick Command Cheatsheet, you can import/open directly to you ONE NOTE.☆10Updated 3 years ago
- Burp Suite Extension to monitor new scope☆17Updated 3 years ago
- a vulnerable GraphQL application☆18Updated 4 years ago
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆68Updated 4 years ago
- Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops☆42Updated 9 months ago
- A Burp Suite Extension for pentester and bug bounty hunters an to maintain checklist, map flows, write test cases and track vulnerabiliti…☆111Updated last year
- Tracking my journey towards earning my OSCP. This includes the process of everything that I learn along the way.☆47Updated 2 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆27Updated last year
- ☆22Updated 3 years ago
- Publicly availalbe vulnarble by desgin vm/machines☆30Updated 2 years ago
- Penetration Testing Checklist☆35Updated 4 years ago
- OSCP☆37Updated 2 years ago
- Template used for my OSCP exam.☆26Updated 2 years ago
- Extract endpoints marked as disallow in robots files to generate wordlists.☆54Updated 2 years ago
- Create your own recon & vulnerability scanner with Trickest and GitHub☆49Updated last year
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- HTTP parameter discovery suite.☆60Updated 4 years ago
- Scripts that are intended to help you in your pen-testing and bug-hunting efforts by automating various manual tasks, making your work mo…☆74Updated last month
- Checks whether a domain is hosted on a cloud service such as AWS, Azure or CloudFlare☆58Updated last year
- ☆17Updated 2 years ago
- A collection of one off hacks and simple scripts☆27Updated last year