snyk-labs / exploit-workshopLinks
A step by step workshop to exploit various vulnerabilities in Node.js and Java applications
☆157Updated last year
Alternatives and similar repositories for exploit-workshop
Users that are interested in exploit-workshop are comparing it to the libraries listed below
Sorting:
- Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).☆123Updated 2 years ago
- Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"☆358Updated 5 years ago
- ☆72Updated 5 years ago
- vulnerable single sign on☆148Updated last year
- A tool geared towards pentesting APIs using OpenAPI definitions.☆183Updated 3 years ago
- Everything you need about Burp Extension Generation☆157Updated 3 years ago
- ☆45Updated 5 years ago
- ☆148Updated 3 years ago
- Workshop given at Hack in Paris 2019☆126Updated 2 years ago
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters☆110Updated 2 years ago
- A lab to play with authentication and authorisation problems☆98Updated 2 years ago
- This repository contains an example Python API that is vulnerable to several different web API attacks.☆70Updated last year
- A step-by-step walkthrough of CloudGoat 2.0 scenarios.☆134Updated 5 years ago
- ☆173Updated 2 years ago
- [A]ndroid [A]pplication [P]entest [G]uide☆122Updated 6 years ago
- CollabOzark is a simple tool which helps the researchers track SSRF, RCE, Blind XSS, XXE, External Resource Access payloads triggers.☆135Updated 6 years ago
- Pentesting/Bugbounty Dockerfiles.☆176Updated 4 years ago
- Damn Vulnerable Java (EE) Application☆144Updated last year
- Burp Suite Extension to monitor new scope☆200Updated 4 years ago
- Reclaim control of your Burp Suite Repeater tabs with this powerful extension☆68Updated 4 years ago
- A set of simple servers (currently HTTP/HTTPS and DNS) which allow configurable and scriptable responses to network requests.☆62Updated 3 years ago
- A place to store my own wordlists, and link to others that are useful☆108Updated 2 years ago
- This repository contains all the material from the talk "Practical recon techniques for bug hunters & pentesters" given at Bugcrowd Level…☆62Updated 6 years ago
- This Burpsuite plugin allows for multiple web app testers to share their proxy history with each other in real time. Requests that comes …☆261Updated 3 years ago
- MetaSec.js combines all the free open-source security tools to identify issues with JavaScript and automates the boring parts☆82Updated 2 years ago
- A natural evolution of Burp Suite's Repeater tool☆200Updated last year
- Fuzzing Payloads to Assist in Web Application Testing.☆167Updated 6 years ago
- A curated list of amazingly bug bounty tips from security researchers around the world.☆104Updated 6 years ago
- Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in …☆206Updated 2 years ago
- A deep look at some recon methodologies and web-application vulnerabilities of my interest where I will merge all my notes gathered from …☆109Updated 3 years ago