Dylan Ayrey
Dylan Ayrey
AttackingAndDefendingTheGCPMetadataAPI
This repo gives an overview of some GCP metadata API attack and defend patterns
CORS
JSON API's Are Automatically Protected Against CSRF, And Google Almost Took It Away.
CSRF-PoC-Genorator
This is a simple CSRF Proof of Concept generator that supports multiple form encodings and methods
Damn-Vulnerable-Redis-Container
An example of obtaining RCE via Redis and CSRF
gcploit
These are tools we released with our 2020 defcon/blackhat talk https://www.youtube.com/watch?v=Ml09R38jpok
bygonessl
A tool to discover bygonessl vulnerabilities using the facebook API
logger
Simple javascript logging of fingerprint, IP address and user agent