
CVE-2018-19131
Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Proof-of-Concept exploit of CVE-2018-19131: Squid Proxy XSS via X.509 Certificate

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Hackable HTTP proxy for resiliency testing and simulated network conditions

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

High-speed Burp Suite extension for sending large volumes of HTTP requests with a custom stack, Python-based attack configuration, and advanced…

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL…

Deliberately vulnerable microservices API designed for hands-on training in the OWASP API Security Top 10 risks, with built-in challenges and a…

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Vulnerability scanner based on vulners.com search API

Automated HTTP Request Repeating With Burp Suite


All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

Detects and exploits HTTP request smuggling vulnerabilities via HTTP/2 to HTTP/1.1 conversion, using automated header smuggling techniques to…

a Damn Vulnerable Serverless Application

Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.

Search for Directory Traversal Vulnerabilities

SAML2 Burp Extension