tuannq2299 / semgrep-rules
A collection of Semgrep rules which followed security guidelines for .NET and Java.
☆16Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for semgrep-rules
- An extension to use Semgrep inside Burp Suite.☆88Updated last year
- A collection of my Semgrep rules☆47Updated last year
- Proof-of-concept code for research into GitHub Actions Cache poisoning.☆22Updated 3 months ago
- Manager of third-party sources of Semgrep rules 🗂☆76Updated 4 months ago
- Encode and Fuzz Custom Protobuf Messages in Burp Suite☆30Updated last year
- Proof of Concepts for unsafe deserialization in Ruby☆14Updated last month
- ☆44Updated 4 years ago
- ☆15Updated 3 years ago
- Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes☆30Updated last year
- ☆92Updated 3 years ago
- FastCVE - fast, rich and API-based search for CVE and more (CPE, CWE, CAPEC)☆39Updated 3 months ago
- Dependency Confusion Security Testing Tool☆39Updated 2 years ago
- flask-webgoat is a deliberately-vulnerable application written with the Flask web framework.☆19Updated 4 months ago
- Compiled dataset of Java deserialization CVEs☆60Updated 4 years ago
- An HTTP Response fuzzer to find Vulnerabilities in Security Scanners☆26Updated 5 months ago
- PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams☆98Updated 9 months ago
- Performing automated scan using Burp Suite Pro & Vmware Burp Rest API☆49Updated 2 years ago
- yataf extracts secrets and paths from files or urls - its best used against javascript files☆51Updated 2 months ago
- A curated list of argument injection vectors☆37Updated 2 months ago
- A web server designed to shut off on command to exploit DNS rebinding in Chromium-based browsers☆11Updated last year
- ☆175Updated 2 weeks ago
- Static Token And Credential Scanner☆95Updated last year
- TheThing: an open-source tool to detect DOM Clobbering vulnerabilities☆40Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆52Updated this week
- Same Origin XSS challenge☆56Updated 2 years ago
- ☆158Updated 3 years ago
- Testability Pattern Catalogs for SAST☆29Updated 8 months ago
- Chrome extension to detect possible xsleaks☆12Updated 5 years ago
- Paramalyzer - Burp extension for parameter analysis of large-scale web application penetration tests.☆29Updated 2 years ago
- Additional active scan checks for BURP☆20Updated last month