nikitastupin / pwnhub
How GitHub Actions workflows can be hacked
β105Updated 2 months ago
Related projects β
Alternatives and complementary repositories for pwnhub
- Manager of third-party sources of Semgrep rules πβ76Updated 4 months ago
- β175Updated 2 weeks ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagramsβ98Updated 9 months ago
- Script to audit GitHub Action Workflow files for potential vulnerabilities.β151Updated 2 months ago
- Octoscan is a static vulnerability scanner for GitHub action workflows.β171Updated last week
- A collection of Server-Side Prototype Pollution gadgets and exploitsβ133Updated 2 months ago
- β83Updated 4 months ago
- Create notes during a security code review in VSCode π Import your favorite SAST tool findings π οΈ and collaborate with others π€β131Updated last year
- PP-finder Help you find gadget for prototype pollution exploitationβ138Updated 3 months ago
- Find authentication (authn) and authorization (authz) security bugs in web application routes.β252Updated 4 months ago
- Client-Side Prototype Pollution Toolsβ84Updated 3 years ago
- GitHub Attack Toolkit - Extreme Editionβ196Updated this week
- A curated list of awesome browser security learning material.β130Updated 2 years ago
- An extension to use Semgrep inside Burp Suite.β88Updated last year
- Semgrep queries developed by Trail of Bits.β330Updated this week
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizationsβ52Updated this week
- β88Updated 11 months ago
- Awesome MXSS ??β45Updated last month
- Searcher for cross-site leaks (XS-Leaks)β81Updated last year
- boostsecurityio/lotpβ101Updated 7 months ago
- β143Updated last month
- Proof-of-concept code for research into GitHub Actions Cache poisoning.β22Updated 3 months ago
- β69Updated 2 years ago
- This tool analyzes a given Github repository and searches for dangling or force-pushed commits containing potential secret or interestingβ¦β146Updated 3 months ago
- List of Trusted Types bypassesβ86Updated 7 months ago
- openrisk is a tool that generates a risk score based on the results of a Nuclei scan.β166Updated 6 months ago
- Find CVE PoCs on GitHubβ137Updated last year
- Distribute ordinary bash commands over many systemsβ161Updated 2 years ago
- jws2pubkey toolβ37Updated 5 months ago
- β65Updated last month