leaky-forms / leaky-forms-crawler
Puppeteer based crawler to measure email and password exfiltration
☆21Updated 2 years ago
Alternatives and similar repositories for leaky-forms-crawler:
Users that are interested in leaky-forms-crawler are comparing it to the libraries listed below
- OmniCrawl is a web measurement tool that allows for recording of web requests and JavaScript browser API accesses on multiple platforms.☆25Updated 11 months ago
- Damn Vulnerable ElectronJS App (DVEA)☆13Updated 2 months ago
- List of periodically validated public DNS resolvers☆23Updated this week
- Code for our 2023 IEEE S&P Paper "The Leaky Web: Automated Discovery of Cross-Site Information Leaks in Browsers and the Web"☆13Updated 2 months ago
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆44Updated last year
- ☆15Updated 3 years ago
- Using EPUBs for the semi-automated evaluation of security and privacy implications of EPUB reading systems.☆31Updated 2 years ago
- Python script implementing the favicon hash trick to find subdomains.☆28Updated last year
- A repository of the 10 million live most popular websites☆40Updated 2 years ago
- Dependency Confusion Security Testing Tool☆45Updated 2 years ago
- Static analysis of wordpress plugins☆63Updated 4 years ago
- GH Scanner Tool is written in Python3 and designed for penetration testers and bug bounty hunters to scan Organization/User repositories …☆33Updated 9 months ago
- spk aka spritzgebaeck: A small OSINT/Recon tool to find CIDRs that belong to a specific organization.☆83Updated last month
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆48Updated 3 months ago
- AXFR all the things!☆24Updated last month
- Signatures for wraith used to detect secrets across various sources☆15Updated 2 years ago
- Collection of wordlists containing dangerous function calls in many languages☆24Updated this week
- WebSocket Connection Smuggler☆44Updated 2 years ago
- Unicode characters that will translate a single character to multiple characters in domain names or TLD's☆40Updated 2 months ago
- An incomplete listing of `.mil` domains and the code for the scraper used to build the list☆51Updated 9 years ago
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆32Updated 2 years ago
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆10Updated 7 months ago
- ☆70Updated 3 years ago
- Database to store previously found subdomains☆60Updated 2 years ago
- Burp plugin for the 1Password session protocol for use by security researchers.☆62Updated 2 months ago
- DNS resolver pools written in Go☆43Updated 6 months ago
- Scripts for Sourcegraph search results. Useful for static analysis <3☆26Updated last year
- Wordlists for Bug Bounty☆25Updated 5 years ago
- The official wrapper for spyse.com API, written in Go, aimed to help developers build their integrations with Spyse.☆28Updated 3 years ago
- A collection of domain lists obtained from zone-walking TLDs. Updated daily.☆21Updated this week