stypr / vulnerable-nodejs-express-mysql
Example of a vulnerable NodeJS+Express+MySQL service
☆20Updated 2 years ago
Alternatives and similar repositories for vulnerable-nodejs-express-mysql:
Users that are interested in vulnerable-nodejs-express-mysql are comparing it to the libraries listed below
- Client-Side Prototype Pollution Tools☆84Updated 3 years ago
- Searcher for cross-site leaks (XS-Leaks)☆82Updated 2 years ago
- List of Trusted Types bypasses☆88Updated 10 months ago
- Chrome extension to detect possible xsleaks☆12Updated 5 years ago
- ☆15Updated 3 years ago
- A extension for collecting parameters☆25Updated 4 years ago
- Lab that will help you to understand how type juggling vulnerability works.☆22Updated 4 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆31Updated 2 years ago
- Identifies vulnerabilities in network_security_config.xml, AndroidManifest.xml and if Firebase URL are accessible publicly☆47Updated last year
- DOM Clobbering Wiki, Browser Testing, and Payload Generation☆48Updated 3 months ago
- ☆57Updated last month
- Prototype Pollution exploits collection☆31Updated 3 years ago
- a tool that compiles a csv of all h1 program stats☆46Updated last year
- Extract SSL certificate data (Subject Name, Subject Alt Names, Organisation)☆42Updated 2 weeks ago
- Server and avi file to exploit FFmpeg HLS parse☆22Updated 5 years ago
- Collection of quirky behaviours of code and the CTF challenges that I made around them.☆27Updated 4 years ago
- Extract relative urls from a heap snapshot☆85Updated 3 years ago
- Same Origin XSS challenge☆56Updated 2 years ago
- ☆46Updated 3 years ago
- HTTP request smuggling tools☆18Updated 4 years ago
- ☆56Updated 3 years ago
- Script to test open Akamai ARL vulnerability.☆70Updated 3 years ago
- Get all the CNs from a list of domains☆46Updated 3 years ago
- In this repository I'll host my research and methodologies for auditing vulnerabilities☆30Updated 5 years ago
- A repository of wordlists for enumeration. Will be added to by my tools when they find interesting new entries☆22Updated 4 years ago
- This Burp extension helps you to find usages of postMessage and recvMessage☆15Updated 5 years ago
- The format of various s3 buckets is convert in one format. for bugbounty and security testing.☆84Updated last year
- ☆23Updated 2 years ago
- Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard.☆33Updated 3 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 2 years ago