p4k03n4t0r / http-request-smugglingLinks
Blog about HTTP Request Smuggling, including a demo application.
☆33Updated 3 years ago
Alternatives and similar repositories for http-request-smuggling
Users that are interested in http-request-smuggling are comparing it to the libraries listed below
Sorting:
- Searcher for cross-site leaks (XS-Leaks)☆83Updated 2 years ago
- ☆56Updated 4 years ago
- Security Advisories☆35Updated last month
- Same Origin XSS challenge☆64Updated 3 years ago
- ☆25Updated 8 months ago
- HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets☆35Updated 3 years ago
- ☆41Updated 3 weeks ago
- Awesome MXSS ??☆55Updated last year
- Challenges I wrote for various CTF competitions☆45Updated last year
- ☆27Updated 2 years ago
- Updated version of the ProtoBurp Extension, with enhanced features and capabilities to encode and fuzz custom protobuf messages☆36Updated 2 years ago
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆28Updated 7 years ago
- A collection of utilities for building extensions using Burp's Montoya API☆52Updated last month
- This repository contains various XXE labs set up for different languages and their different parsers. This may alternatively serve as a p…☆112Updated last year
- Prototype Pollution exploits collection☆35Updated 4 years ago
- CTF challenges WriteUp☆14Updated 3 years ago
- a repository of all the CTF challenges I've made for public events☆58Updated 4 months ago
- LFI to RCE via phpinfo() assistance or via controlled log file☆72Updated 2 years ago
- A PoC code for JSON Smuggling technique to smuggle arbitrary files through JSON☆114Updated last year
- A cheatsheet for exploiting server-side SVG rasterization.☆30Updated 3 years ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆57Updated 2 months ago
- Script to exploit Grafana CVE-2025-4123: XSS and Full-Read SSRF☆51Updated 4 months ago
- Guided Differential Fuzzing for HTTP Request Parsing Discrepancies☆20Updated last year
- Improve automated and semi-automated active scanning in Burp Pro☆62Updated 6 months ago
- Android webviews and securiy☆23Updated 2 months ago
- A collection of Burp Suite Lambda Filters ~ Bambdas☆29Updated last year
- ☆169Updated 4 years ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆34Updated 9 months ago
- lightyear is a tool to dump files in tedious (blind) conditions using PHP filters☆107Updated 5 months ago
- Pipe nmap verbose output to a usable format for httpx or host:port notation.☆17Updated 3 years ago