A reusable workflow for running tests for .NET projects.
-
Updated
Aug 24, 2026
8000
A reusable workflow for running tests for .NET projects.
this is (xss, sqli , commend injection , ssrf ,etc) Payloads
secMONSTER performs 150+ security tests including XSS, SQLi, RCE, SSRF, LFI, SSTI, XXE, NoSQL, CMDi, CRLF, open redirect, JWT attacks, OAuth/SAML bypass, cloud metadata (AWS/GCP/Azure), container escape, Kubernetes, WebSocket, HTTP/2, DNS rebinding, QUIC, API/GraphQL, AI prompt injection, Web3/DeFi, and comprehensive vulnerability exploitation
Penetration Testing Sandbox simulated environment for bug bounty hunters. Master 8 common vulnerability challenges (SQLi, XSS, IDOR, SSRF, SSTI, XXE) in a 100% safe, browser-based lab
Bilingual writeup for OverTheWire Natas (35 levels). Step-by-step solutions, vulnerability analysis, defense strategies, and code examples. Features neon UI, terminal simulation, and progress tracking. Perfect for web security learning.
A hands-on web security home lab covering web vulnerabilities, REST API security, authentication, authorization, and defensive security.
Educational Django SCADA maintenance interface demonstrating vulnerable and patched OT security workflows.
Fourteen cybersecurity laboratory reports, 182 pages: classical cryptanalysis and entropy through PKI, network reconnaissance and web application exploitation
Security audit of XML external entity processing. Bug bounty and vulnerability disclosure program.
XML parser for JavaScript with namespaces, DTD controls, canonical XML output, and validation helpers.
Lint or sanitize untrusted SVG in pure Ruby, catch scripts, XSS, XXE, external references, and render bombs before you render or embed it
Reproducible Hackergram web-security lab covering SQLi, XSS, CSRF, SSRF, XXE, NoSQL injection, LLM-mediated attacks, GNS3 evidence collection, and hardened retesting.
Security assessment of OWASP WebGoat using GitHub CodeQL static analysis - findings on XXE, SSRF, insecure deserialization, and SQL injection with remediation.
ArubaOS 8.13.2.0 pre-auth attack surface research. XXE+SSRF, ICMP reflection, buffer over-read, hardcoded credentials — all submitted to HPE Bugcrowd, marked N/A. No fixes issued.
Notes from TryHackMe's Web Application Pentesting path. Goes beyond OWASP Top 10 basics into JWT and OAuth attacks, NoSQL/XXE/SSTI/LDAP injection, SSRF, insecure deserialization, and HTTP request smuggling across HTTP/1.1, HTTP/2, and WebSockets, with full kill chain writeups for each module's challenge room.
VAPT Master Checklist for web application vulnerabilities, including detailed checklists and techniques for various attack vectors.
Add a description, image, and links to the xxe topic page so that developers can more easily learn about it.
To associate your repository with the xxe topic, visit your repo's landing page and select "manage topics."