mariussteffens / pmforceLinks
Source code for ACM CCS 2020 Paper PMForce: Systematically Analyzing postMessage Handlers at Scale
☆18Updated 4 years ago
Alternatives and similar repositories for pmforce
Users that are interested in pmforce are comparing it to the libraries listed below
Sorting:
- ☆18Updated 7 years ago
- ☆17Updated 2 years ago
- TaintFlow, a framework for JavaScript dynamic information flow analysis.☆18Updated 3 years ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆42Updated last year
- A web browser with dynamic data-flow tracking enabled in the Javascript engine and DOM, based on Mozilla Firefox (https://github.com/mozi…☆155Updated last week
- Generic SAST Library☆135Updated 7 months ago
- A Simple command line tool that helps checking web applications to identify insecure deserialization vulnerabilities.☆24Updated 6 years ago
- Dockerfile for AFL++ and helpful other tools☆21Updated 5 years ago
- COVA - A static analysis tool to compute path conditions☆40Updated 6 months ago
- ☆47Updated 5 years ago
- Downloader for Firefox/jsshell/Thunderbird builds for fuzzing.☆43Updated last month
- ☆20Updated 8 years ago
- This is the repository for JÄk. I created it as prototype during my masterthesis.☆31Updated 8 years ago
- Run CodeQL queries at scale using Multi-Repository Variant Analysis (MRVA)☆62Updated 9 months ago
- Grammar-based HTTP/2 fuzzer with mutation ability☆47Updated 3 years ago
- Scripts and auxiliary files for fuzzing PHP's unserialize function☆46Updated 8 years ago
- This novel black-box web vulnerability scanner attempts to infer the state machine of the web application.☆19Updated 5 years ago
- Testability Pattern Catalogs for SAST☆31Updated 11 months ago
- ☆82Updated 5 months ago
- Statically Detecting Vulnerable Data Flows in Browser Extensions at Scale☆79Updated 4 years ago
- Symbolic execution inspired PHP application scanner for code-path discovery☆34Updated 6 years ago
- An HTTP Response fuzzer to find Vulnerabilities in Security Scanners☆27Updated last year
- Improving security and resilience of WebAssembly VMs/runtimes/parsers using fuzzing☆96Updated last year
- CTF writeup for learning☆22Updated 4 years ago
- HTTP Desync Attack☆28Updated 5 years ago
- A Node.js vulnerability finding tool.☆96Updated 5 months ago
- WinDbg script to spoof origin and url of a renderer process in Chrome☆25Updated 5 years ago
- Fuzz testing: Beginner's guide☆76Updated last year
- ☆19Updated 10 years ago
- Record my learn path of HEAP EXPLOITATION on LINUX☆14Updated 8 years ago