Aon's Cyber Solutions - Security Testing (Formerly GDS) (GDSSecurity)

Aon's Cyber Solutions - Security Testing (Formerly GDS)

GDSSecurity

Geek Repo

Location:New York, NY

Home Page:https://www.aon.com/cyber-solutions

Github PK Tool:Github PK Tool

Aon's Cyber Solutions - Security Testing (Formerly GDS)'s repositories

GWT-Penetration-Testing-Toolset

A set of tools made to assist in penetration testing GWT applications. Additional details about these tools can be found on my OWASP Appsec DC slides available here: http://www.owasp.org/images/7/77/Attacking_Google_Web_Toolkit.ppt

wifitap

wifitap updated for BT5r3

Language:PythonLicense:GPL-2.0Stargazers:152Issues:27Issues:1

Jetleak-Testing-Script

Script to test if a server is vulnerable to the JetLeak vulnerability

SQLBrute

SQLBrute is a tool for brute forcing data out of databases using blind SQL injection vulnerabilities.

Language:PythonStargazers:71Issues:25Issues:0

GDS-PMD-Security-Rules

Custom security ruleset for the popular Java static analysis tool PMD.

Language:JavaLicense:GPL-2.0Stargazers:60Issues:11Issues:2

Whitepapers

A collection of publicly released whitepapers

WCF-Binary-SOAP-Plug-In

This is a Burp Suite plug-in designed to encode and decode WCF Binary Soap request and response data ("Content-Type: application/soap+msbin1). There are two versions of the plug-in available (consult the README for more information).

Language:C#Stargazers:45Issues:20Issues:0

PSAttack

A portable console aimed at making pentesting with PowerShell a little easier.

Language:C#License:MITStargazers:44Issues:10Issues:0

burpee

Python object interface to requests/responses recorded by Burp Suite

Language:Objective-CLicense:GPL-2.0Stargazers:23Issues:85Issues:0
Language:PythonLicense:GPL-2.0Stargazers:22Issues:86Issues:0

Anti-CSRF-Library

This library was co-developed with a leading financial institution in order to build a single solution for Cross-Site Request Forgery (CSRF) prevention that is flexible enough to deploy firm-wide within diverse Java/J2EE web application environments.

Language:JavaLicense:Apache-2.0Stargazers:20Issues:26Issues:1
Language:C#License:GPL-2.0Stargazers:20Issues:85Issues:0

AntiXSS-for-Java

AntiXSS for Java is a port of the Microsoft Anti-Cross Site Scripting (AntiXSS) v1.5 library for .NET applications. The library requires Java 1.4 or higher, but has no other prerequisites.

Language:JavaStargazers:16Issues:28Issues:0

sol-function-profiler

Solidity Contract Function Profiler

Language:JavaScriptLicense:MITStargazers:16Issues:5Issues:0

Code-from-O-reilly-Network-Security-Tools

Tools developed for the book Network Security Tools: Writing, Hacking, and Modifying Security Tools (Published April 2005 by O'Reilly - ISBN 0-596-00794-9). These examples, along with the rest of the examples from the book, are also available from O'Reilly.

Language:PerlStargazers:15Issues:20Issues:0

JSSE_Fortify_SCA_Rules

Custom Fortify SCA rules to detect common JSSE certification validation flaws

Language:JavaLicense:GPL-2.0Stargazers:11Issues:87Issues:0

SSLSecurityChecker

IronWASP module to test security of SSL services. Ported from http://www.bolet.org/TestSSLServer/

Language:C#Stargazers:11Issues:7Issues:0

Presentations

This repository contains slide decks and other materials for talks and research presented at various conferences.

SubstrateDemo

ListLock APK contains the demo APK for the Using Mobile Substrate With Android Applications blog post

Language:JavaLicense:GPL-3.0Stargazers:9Issues:21Issues:0

sentrygun

Rogue AP killer

Language:PythonStargazers:7Issues:9Issues:0

blazentoo

Blazentoo is an Adobe AIR application that can be used to exploit insecure Adobe BlazeDS and LiveCycle Data Services ES servers. Blazentoo provides the ability to seamlessly browse web content, abusing insecurely configured Proxy Services.

Convert2FPR

Utility for converting Findbugs, ESLint and PMD XML results into HP Fortify FPRs

Language:XSLTLicense:GPL-2.0Stargazers:6Issues:85Issues:0

Scala-Findbugs-Sample

Sample Findbugs custom detector for finding potentially insecure Scala code.

Language:JavaStargazers:5Issues:21Issues:0
Language:JavaLicense:NOASSERTIONStargazers:5Issues:17Issues:0

mimegusta

Configurable content-sniffing XSS test bed

Language:PHPStargazers:4Issues:6Issues:0

sslscan

sslscan tests SSL/TLS enabled services to discover supported cipher suites

Language:CLicense:GPL-3.0Stargazers:3Issues:5Issues:0

fusionpbx

Official FusionPBX - A full-featured domain based multi-tenant PBX and voice switch for FreeSwitch.

Language:PHPStargazers:0Issues:5Issues:0