mandatoryprogrammer / tarnishLinks
A Chrome extension static analysis tool to help aide in security reviews.
☆156Updated 2 years ago
Alternatives and similar repositories for tarnish
Users that are interested in tarnish are comparing it to the libraries listed below
Sorting:
- Improved decoder for Burp Suite☆138Updated 4 years ago
- Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website☆138Updated 5 years ago
- Files for appsecwiki.com☆119Updated 5 years ago
- ReconJSON is a project dedicated to creating a flexible and consistent JSON format across popular recon tools.☆102Updated 6 years ago
- [A]ndroid [A]pplication [P]entest [G]uide☆124Updated 5 years ago
- A repository for GraphQL Extension for Burp Suite☆57Updated 6 years ago
- The DetectDynamicJS Burp Extension provides an additional passive scanner that tries to find differing content in JavaScript files and ai…☆67Updated 5 years ago
- Bodhi - Client-side Vulnerability Playground☆121Updated 4 years ago
- Tools to gather subdomains from Bug Bounty programs☆65Updated 7 years ago
- Application and Service Fingerprinting☆133Updated 2 years ago
- A tool for enumerating expired domains in CNAME records☆59Updated 9 years ago
- Kurukshetra - A framework for teaching secure coding by means of interactive problem solving.☆140Updated 11 months ago
- A Burp Plugin for Detecting Weaknesses in Content Security Policies☆168Updated 2 years ago
- HTML5 WebSocket message fuzzer☆146Updated 6 years ago
- Burp Suite extension to generate Intruder payloads using Radamsa☆89Updated 8 years ago
- Simple wrapper for meg that sieves through meg's output for you.☆60Updated 5 years ago
- A very simple bridge for performing Flash HTTP requests with JavaScript☆80Updated 10 years ago
- Automate common Chrome Debug Protocol tasks to help debug web applications from the command-line and actively monitor and intercept HTTP …☆73Updated 4 years ago
- AutoTriageBot automatically verifies, deduplicates, and suggests payouts for incoming HackerOne reports.☆56Updated 3 years ago
- Nodejs application intentionally vulnerable to SSRF☆42Updated 2 years ago
- A tool to evaluate Content Security Policies.☆72Updated 5 years ago
- Transparently log all data passed into known JavaScript sinks - Sink Logger extension for Burp.☆49Updated 3 years ago
- Pillage a git repo found in an accessible web root☆61Updated 14 years ago
- Extension providing view with filtering capabilities for both complete and incomplete requests from all burp tools.☆47Updated 4 years ago
- Burp Suite extension to passively scan for applications revealing server error messages☆65Updated last year
- Evenly distributes scanner load across targets☆92Updated 5 months ago
- A bash script that fetches and maintains thousands of DNS resolvers☆65Updated 5 years ago
- Proof-of-concept CORS exploitation tool.☆35Updated 6 years ago
- DupeKeyInjector☆135Updated 3 years ago
- A central place to keep track of relevant BountyMachine talks, blogs, and interesting things!☆33Updated 6 years ago