nccgroup / RFC-Security-Research
Paper, data and code from Investigating Potential Security Vulnerability Manifestation through Various Analyses & Inferences Regarding Internet RFCs
☆18Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for RFC-Security-Research
- A multi-threaded scanner that helps identify CORS flaws/misconfigurations☆18Updated 4 years ago
- Signatures for wraith used to detect secrets across various sources☆15Updated 2 years ago
- A playground to practice SSRF Attacks against web apps☆17Updated 6 years ago
- A parallel scanner that utilises axiom to spin up servers and parallel scan using masscan.☆16Updated 4 years ago
- Swiftly search FDNS datasets from Rapid7 Open Data☆21Updated last year
- Kubernetes Scanner☆41Updated 2 years ago
- String or worldlist encoder for use in fuzzing or web application testing☆17Updated 5 years ago
- This is a Burpsuite plugin built to enable you to import your directory bruteforcing results into burp for easy viewing later. This is an…☆36Updated last year
- LetMeOutOfYour.net Resources☆20Updated 4 years ago
- Clickjacking PoC Generator☆35Updated 4 years ago
- Tools for auditing WAFS☆18Updated 2 years ago
- Supporting material for the "Hunting Bugs In The Tropics" DEFCON 30 talk☆9Updated 2 years ago
- A bash script that automates the scanning of a target network for HTTP resources through XXE☆37Updated 3 years ago
- Extensive code infrastructure for finding unintended information leaks in files, git repositories and much more.☆28Updated 2 years ago
- Jira Secret Hunter - Helps you find credentials and sensitive contents in Jira tickets☆42Updated last year
- OWASP ZAP add-on to detect reflected parameter vulnerabilities efficiently☆12Updated 3 years ago
- ☆10Updated 5 years ago
- A rogue DNS detector☆23Updated last year
- Burp Suite Pro extension☆10Updated 7 years ago
- During pentesting I often miss screenshots of events for reports due to the quick pace of testing and a lack of foreknowledge about what …☆25Updated 5 years ago
- Docker Version of Aquatone☆13Updated 6 years ago
- A better dns bruteforcer written in golang☆13Updated 6 years ago
- ☆18Updated 7 years ago
- Multithreaded Padding Oracle Attack on Oracle OAM (CVE-2018-2879)☆24Updated 5 years ago
- An information gathering tool to collect git emails in version control host services☆11Updated 5 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆13Updated 2 years ago
- Slides and demo code for past presentations☆11Updated 2 years ago
- Quick WAF "paranoid" Doctor Evaluation | WAFPARAN01D3 Tool☆25Updated 2 years ago
- ☆20Updated 4 years ago
- Interactsh deployment to AWS EC2 Instance with Terraform☆11Updated 2 years ago