├── README.md ├── browser-extensions ├── clear_cache-3.2-fx.xpi ├── cookie_quick_manager-0.5rc2-an+fx.xpi ├── dark_reader-4.9.42-an+fx.xpi └── eval_villain-2.6-fx.xpi ├── wordlists ├── content-types.txt ├── extensions.txt ├── http-headers.txt ├── http-methods.txt ├── params.txt ├── protocols.txt └── special-chars.txt └── zap-scripts ├── authentication ├── StarbucksKRLogin.js └── StarbucksKRLogin.zst ├── fuzzer-http-processor ├── addCacheBusting.js ├── random-x-forwarded-for.js ├── setFilter.js └── setMatcher.js ├── passive ├── findCookieSameSiteNone.js ├── findDOMClobbering.js └── findPrototypePollution.js ├── payloadgenerator └── blindRCEwithOAST.js ├── proxy ├── fake-response.js └── replace-in-req-url.zest ├── standalone ├── disableProxy.js ├── enableProxy.js └── remove404.js └── targeted ├── copy-curl.js └── make-csrf-poc.js /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/README.md -------------------------------------------------------------------------------- /browser-extensions/clear_cache-3.2-fx.xpi: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/browser-extensions/clear_cache-3.2-fx.xpi -------------------------------------------------------------------------------- /browser-extensions/cookie_quick_manager-0.5rc2-an+fx.xpi: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/browser-extensions/cookie_quick_manager-0.5rc2-an+fx.xpi -------------------------------------------------------------------------------- /browser-extensions/dark_reader-4.9.42-an+fx.xpi: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/browser-extensions/dark_reader-4.9.42-an+fx.xpi -------------------------------------------------------------------------------- /browser-extensions/eval_villain-2.6-fx.xpi: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/browser-extensions/eval_villain-2.6-fx.xpi -------------------------------------------------------------------------------- /wordlists/content-types.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/content-types.txt -------------------------------------------------------------------------------- /wordlists/extensions.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/extensions.txt -------------------------------------------------------------------------------- /wordlists/http-headers.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/http-headers.txt -------------------------------------------------------------------------------- /wordlists/http-methods.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/http-methods.txt -------------------------------------------------------------------------------- /wordlists/params.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/params.txt -------------------------------------------------------------------------------- /wordlists/protocols.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/protocols.txt -------------------------------------------------------------------------------- /wordlists/special-chars.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/wordlists/special-chars.txt -------------------------------------------------------------------------------- /zap-scripts/authentication/StarbucksKRLogin.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/authentication/StarbucksKRLogin.js -------------------------------------------------------------------------------- /zap-scripts/authentication/StarbucksKRLogin.zst: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/authentication/StarbucksKRLogin.zst -------------------------------------------------------------------------------- /zap-scripts/fuzzer-http-processor/addCacheBusting.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/fuzzer-http-processor/addCacheBusting.js -------------------------------------------------------------------------------- /zap-scripts/fuzzer-http-processor/random-x-forwarded-for.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/fuzzer-http-processor/random-x-forwarded-for.js -------------------------------------------------------------------------------- /zap-scripts/fuzzer-http-processor/setFilter.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/fuzzer-http-processor/setFilter.js -------------------------------------------------------------------------------- /zap-scripts/fuzzer-http-processor/setMatcher.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/fuzzer-http-processor/setMatcher.js -------------------------------------------------------------------------------- /zap-scripts/passive/findCookieSameSiteNone.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/passive/findCookieSameSiteNone.js -------------------------------------------------------------------------------- /zap-scripts/passive/findDOMClobbering.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/passive/findDOMClobbering.js -------------------------------------------------------------------------------- /zap-scripts/passive/findPrototypePollution.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/passive/findPrototypePollution.js -------------------------------------------------------------------------------- /zap-scripts/payloadgenerator/blindRCEwithOAST.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/payloadgenerator/blindRCEwithOAST.js -------------------------------------------------------------------------------- /zap-scripts/proxy/fake-response.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/proxy/fake-response.js -------------------------------------------------------------------------------- /zap-scripts/proxy/replace-in-req-url.zest: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/proxy/replace-in-req-url.zest -------------------------------------------------------------------------------- /zap-scripts/standalone/disableProxy.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/standalone/disableProxy.js -------------------------------------------------------------------------------- /zap-scripts/standalone/enableProxy.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/standalone/enableProxy.js -------------------------------------------------------------------------------- /zap-scripts/standalone/remove404.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/standalone/remove404.js -------------------------------------------------------------------------------- /zap-scripts/targeted/copy-curl.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/targeted/copy-curl.js -------------------------------------------------------------------------------- /zap-scripts/targeted/make-csrf-poc.js: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/hahwul/fuzzstone/HEAD/zap-scripts/targeted/make-csrf-poc.js --------------------------------------------------------------------------------