p4k03n4t0r / http-request-smuggling
Blog about HTTP Request Smuggling, including a demo application.
☆23Updated 3 years ago
Alternatives and similar repositories for http-request-smuggling:
Users that are interested in http-request-smuggling are comparing it to the libraries listed below
- Same Origin XSS challenge☆56Updated 2 years ago
- ☆94Updated 3 years ago
- ☆25Updated 2 years ago
- Utility for creating ZipSlip archives☆69Updated last year
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆74Updated 2 months ago
- Security Advisories☆32Updated last year
- A collection of Burp Suite Lambda Filters ~ Bambdas☆25Updated 3 months ago
- Improve automated and semi-automated active scanning in Burp Pro☆60Updated 2 years ago
- CTF challenges WriteUp☆14Updated 2 years ago
- A collection of utilities for building extensions using Burp's Montoya API☆48Updated 7 months ago
- A cheatsheet for exploiting server-side SVG rasterization.☆30Updated 2 years ago
- ☆158Updated 3 years ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆27Updated 4 years ago
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets☆33Updated 2 years ago
- Challenges I wrote for various CTF competitions☆40Updated 6 months ago
- Query various sources for CVE proof-of-concepts☆49Updated last year
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆31Updated last year
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆27Updated 6 years ago
- A repository of wordlists for enumeration. Will be added to by my tools when they find interesting new entries☆22Updated 4 years ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- Burp extension to generate multi-step CSRF POC.☆29Updated 5 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- A extension for collecting parameters☆25Updated 4 years ago
- Make better use of the embedded browser that comes by default with Burp☆41Updated last year
- ☆58Updated last year
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago
- ☆69Updated 3 years ago
- Awesome MXSS ??☆47Updated 4 months ago
- ☆34Updated 2 years ago