All Projects → wasec → Similar Projects or Alternatives

222 Open source projects that are alternatives of or similar to wasec

Application Security Engineer Interview Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Stars: ✭ 267 (+260.81%)
Mutual labels:  xss, websecurity
Xss Payload List
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
Stars: ✭ 2,617 (+3436.49%)
Mutual labels:  xss, websecurity
Hacker101
Source code for Hacker101.com - a free online web and mobile security class.
Stars: ✭ 12,246 (+16448.65%)
Mutual labels:  xss, clickjacking
Express Security
nodejs + express security and performance boilerplate.
Stars: ✭ 37 (-50%)
Mutual labels:  csp, xss
Cerberus
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
Stars: ✭ 389 (+425.68%)
Mutual labels:  xss, websecurity
Csp Builder
Build Content-Security-Policy headers from a JSON file (or build them programmatically)
Stars: ✭ 496 (+570.27%)
Mutual labels:  csp, xss
Javasecurity
Java web and command line applications demonstrating various security topics
Stars: ✭ 182 (+145.95%)
Mutual labels:  csp, xss
nuxt-security
Module for Nuxt.js to configure security headers and more
Stars: ✭ 46 (-37.84%)
Mutual labels:  csp
diwa
A Deliberately Insecure Web Application
Stars: ✭ 32 (-56.76%)
Mutual labels:  xss
sanitizer-polyfill
rewrite constructor arguments, call DOMPurify, profit
Stars: ✭ 46 (-37.84%)
Mutual labels:  xss
capture reid
可基于摄像头实时监控或录制的视频或静态图片进行行人检测(lffd)/跟踪(deep sort)和行人重识别(reid)。
Stars: ✭ 87 (+17.57%)
Mutual labels:  csp
XSS-Payload-without-Anything
XSS Payload without Anything.
Stars: ✭ 74 (+0%)
Mutual labels:  xss
gatsby-plugin-csp
A Gatsby plugin which adds strict Content Security Policy to your project.
Stars: ✭ 40 (-45.95%)
Mutual labels:  csp
AspNetCoreMvcAngular
ASP.NET Core MVC with angular in MVC View OpenID Connect Hybrid Flow
Stars: ✭ 54 (-27.03%)
Mutual labels:  csp
HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
Stars: ✭ 1,210 (+1535.14%)
Mutual labels:  websecurity
Resources-for-Application-Security
Some good resources for getting started with application security
Stars: ✭ 97 (+31.08%)
Mutual labels:  websecurity
firecracker
Stop half-done API specifications! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by validating your API specifications.
Stars: ✭ 438 (+491.89%)
Mutual labels:  websecurity
Eagle
Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities
Stars: ✭ 85 (+14.86%)
Mutual labels:  xss
SOMns
SOMns: A Newspeak for Concurrency Research
Stars: ✭ 62 (-16.22%)
Mutual labels:  csp
pentest-notes
渗透测试☞经验/思路/总结/想法/笔记
Stars: ✭ 734 (+891.89%)
Mutual labels:  websecurity
bookmarklets-context-menu
WebExtension allow to execute bookmarklets as privileged scripts
Stars: ✭ 67 (-9.46%)
Mutual labels:  csp
go-csp-collector
A CSP collector written in Golang
Stars: ✭ 74 (+0%)
Mutual labels:  csp
netizenship
a commandline #OSINT tool to find the online presence of a username in popular social media websites like Facebook, Instagram, Twitter, etc.
Stars: ✭ 33 (-55.41%)
Mutual labels:  websecurity
pool
A highly flexible process pooling library for Node.js
Stars: ✭ 18 (-75.68%)
Mutual labels:  csp
caddy-security
🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA/2FA with App Authenticators and Yubico. 💎 Authorization with JWT/PASETO tokens. 🔐
Stars: ✭ 696 (+840.54%)
Mutual labels:  websecurity
solutions-bwapp
In progress rough solutions to bWAPP / bee-box
Stars: ✭ 158 (+113.51%)
Mutual labels:  xss
vue-dompurify-html
Safe replacement for the v-html directive
Stars: ✭ 104 (+40.54%)
Mutual labels:  xss
awesome-web-security
📓 Some notes and impressive articles of Web Security
Stars: ✭ 72 (-2.7%)
Mutual labels:  websecurity
pyGRETA
python Generator of REnewable Time series and mAps
Stars: ✭ 27 (-63.51%)
Mutual labels:  csp
BugHunter
No description or website provided.
Stars: ✭ 23 (-68.92%)
Mutual labels:  clickjacking
plg system httpheader
This is a Joomla Plugin that provides setting of HTTP Headers
Stars: ✭ 19 (-74.32%)
Mutual labels:  csp
hast-util-sanitize
utility to sanitize hast nodes
Stars: ✭ 34 (-54.05%)
Mutual labels:  xss
ssrf-vuls
国光的手把手带你用 SSRF 打穿内网靶场源码
Stars: ✭ 235 (+217.57%)
Mutual labels:  websecurity
persistent-clientside-xss
Exploit generator and Taint Engine to find persistent (and reflected) client-side XSS
Stars: ✭ 19 (-74.32%)
Mutual labels:  xss
bane
this is a python module that contains functions and classes which are used to test the security of web/network applications. it's coded on pure python and it's very intelligent tool ! It can easily detect: XSS (relected/stored), RCE (Remote Code/Command Execution), SSTI, SSRF, CORS Misconfigurations, File Upload, CSRF, Path Traversal,.... Also, …
Stars: ✭ 167 (+125.68%)
Mutual labels:  clickjacking
dhroraryus
Dhroraryus generates schedules intelligently according to one's constraints and preferences
Stars: ✭ 16 (-78.38%)
Mutual labels:  csp
wybug
一款复现wooyun经典漏洞的docker靶机环境
Stars: ✭ 17 (-77.03%)
Mutual labels:  websecurity
APSoft-Web-Scanner-v2
Powerful dork searcher and vulnerability scanner for windows platform
Stars: ✭ 96 (+29.73%)
Mutual labels:  xss
django-http2-middleware
⚡️Django middleware to automatically send preload headers before views runs, enabling faster HTTP2 server-push (with CSP support).
Stars: ✭ 65 (-12.16%)
Mutual labels:  csp
ngx http html sanitize module
It's a nginx http module to sanitize HTML5 with whitelisted elements, whitelisted attributes and whitelisted CSS property
Stars: ✭ 14 (-81.08%)
Mutual labels:  xss
WebSecurityScannerWhitePaper
收集网络上公开的漏洞扫描器的白皮书。
Stars: ✭ 25 (-66.22%)
Mutual labels:  websecurity
functional-core-async
almost, but not quite, entirely unlike core.async
Stars: ✭ 17 (-77.03%)
Mutual labels:  csp
hackable
A python flask app that is purposefully vulnerable to SQL injection and XSS attacks. To be used for demonstrating attacks
Stars: ✭ 61 (-17.57%)
Mutual labels:  xss
NachtWal
Reinforced Mitigation Security Filter
Stars: ✭ 17 (-77.03%)
Mutual labels:  xss
security-cheat-sheet
Minimalist cheat sheet for developpers to write secure code
Stars: ✭ 47 (-36.49%)
Mutual labels:  xss
safe-marked
Markdown to HTML using marked and DOMPurify. Safe by default.
Stars: ✭ 31 (-58.11%)
Mutual labels:  xss
xss-http-injector
XSS HTTP Inject0r is a proof of concept tool that shows how XSS (Cross Site Scripting) flags can be exploited easily. It is written in HTML + Javascript + PHP and released under GPLv3.
Stars: ✭ 22 (-70.27%)
Mutual labels:  xss
csp
A library for Communicating Sequential Processes in Node.js, built on top of async/await
Stars: ✭ 59 (-20.27%)
Mutual labels:  csp
csp.js
📺 CSP for vanilla JavaScript
Stars: ✭ 45 (-39.19%)
Mutual labels:  csp
xssfinder
Toolset for detecting reflected xss in websites
Stars: ✭ 105 (+41.89%)
Mutual labels:  xss
Foxss-XSS-Penetration-Testing-Tool
Foxss is a simple php based penetration Testing Tool.Currently it will help to find XSS vulnerability in websites.
Stars: ✭ 35 (-52.7%)
Mutual labels:  xss
CrySPY
CrySPY is a crystal structure prediction tool written in Python.
Stars: ✭ 58 (-21.62%)
Mutual labels:  csp
csp
Because Security Matters, and Web libraries, tools, and projects, should be more informative about their state.
Stars: ✭ 15 (-79.73%)
Mutual labels:  csp
SuperXSS
Make XSS Great Again
Stars: ✭ 57 (-22.97%)
Mutual labels:  xss
cero
Scrape domain names from SSL certificates of arbitrary hosts
Stars: ✭ 316 (+327.03%)
Mutual labels:  websecurity
flask-vuln
Pretty vulnerable flask app..
Stars: ✭ 23 (-68.92%)
Mutual labels:  xss
vaf
Vaf is a cross-platform very advanced and fast web fuzzer written in nim
Stars: ✭ 294 (+297.3%)
Mutual labels:  xss
security-wrapper
对springSecurity进行二次开发,提供OAuth2授权(支持跨域名,多应用授权)、JWT、SSO、文件上传、权限系统无障碍接入、接口防刷、XSS、CSRF、SQL注入、三方登录(绑定,解绑)、加密通信等一系列安全场景的解决方案
Stars: ✭ 21 (-71.62%)
Mutual labels:  xss
safe-svg
Simple and lightweight library that helps to validate SVG files in security manners.
Stars: ✭ 25 (-66.22%)
Mutual labels:  xss
laravel-xss-filter
Filter user input for XSS but don't touch other html
Stars: ✭ 38 (-48.65%)
Mutual labels:  xss
1-60 of 222 similar projects