sola-da / ReDoS-vulnerabilitiesLinks
A list of ReDoS vulnerabilities in npm modules found by the Software Lab at TU Darmstadt. For each vulnerability, there is a proof-of-concept exploit, showing how the slowdown may occur. The resources in this repository are provided for research purpose only. Please read below for more details.
☆60Updated 8 years ago
Alternatives and similar repositories for ReDoS-vulnerabilities
Users that are interested in ReDoS-vulnerabilities are comparing it to the libraries listed below
Sorting:
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆42Updated last year
- Automatically Preventing Code Injection Attacks on Node.js☆78Updated 3 years ago
- This test suite contains over 40 different test cases that have proven to work with different mobile browsers in my research or testing S…☆30Updated 6 years ago
- A fuzzing library in JavaScript. ✨☆117Updated last week
- X41 Browser Security White Paper - Tools and PoCs☆183Updated 8 years ago
- Another web fuzzer written in NodeJS☆58Updated 7 years ago
- A tool for detecting regular expression denial-of-service vulnerabilities in Android apps.☆36Updated 9 years ago
- Scripts and auxiliary files for fuzzing PHP's unserialize function☆46Updated 8 years ago
- Fuzz testing: Beginner's guide☆76Updated last year
- Dockerfile for AFL++ and helpful other tools☆21Updated 5 years ago
- ☆19Updated 10 years ago
- Proof Of Concept of the BEAST attack against SSL/TLS CVE-2011-3389☆80Updated 7 years ago
- A static-code-analysis tool for performing security-focused code reviews. It enables an auditor to swiftly map the attack-surface of a la…☆142Updated last year
- Cure53 Browser Security White Paper☆300Updated 8 years ago
- BSidesSF CTF 2019 release☆72Updated 3 years ago
- ☆18Updated 7 years ago
- Docker based Wargame Platform - To practice your CTF skills☆32Updated 9 years ago
- some example ctf writeups☆27Updated 5 years ago
- Growing list of potentially dangerous PHP functions☆52Updated 6 years ago
- A front-end JavaScript toolkit for creating DNS rebinding attacks.☆45Updated 7 years ago
- Exploitation challenges for CTF☆63Updated 8 years ago
- ☆72Updated 8 years ago
- A regular expression fuzzer.☆45Updated 7 years ago
- ☆123Updated 4 years ago
- A tool for checking exploitability☆210Updated 6 years ago
- Fuzzing results for various interpreters.☆82Updated 7 years ago
- An extensible, heuristic-based vulnerability scanning tool for installed npm packages☆50Updated 4 years ago
- A Node.js vulnerability finding tool.☆96Updated 6 months ago
- Deprecated: Please visit https://github.com/github/codeql instead.☆81Updated 3 years ago
- Fuzz testing framework for network protocols.☆17Updated 5 years ago