- This repository contains a Secure Social Media application for pentesters called
penconnector
the repository name ispeconnectorlab
.
- Git clone the repo locally
cd /client
npm install
- Next change directories in the to the root of the directory
pentesterlabs
npm install && npm run dev
- Below is a SQL injection mitigation solution, not nosql as this application is nosql based.
After mitigating a vulnerability, you can send a Pull Request to gently ask the secDevLabs community to review your new secure codes. If you're feeling a bit lost, try having a look at this mitigation solution, it might help! 🚀
Disclaimer: You are about to install vulnerable apps in your machine! 🔥
Vulnerability | Language | Application |
---|---|---|
A1 - Injection | Golang | CopyNPaste API |
A1 - Injection | NodeJS | Mongection |
A1 - Injection | Python | SSType |
A2 - Broken Authentication | Python | Saidajaula Monster Fit |
A2 - Broken Authentication | Golang | Insecure go project |
A3 - Sensitive Data Exposure | Golang | SnakePro |
A4 - XML External Entities (XXE) | PHP | ViniJr Blog |
A5 - Broken Access Control | Golang | Vulnerable Ecommerce API |
A5 - Broken Access Control | NodeJS | Tic-Tac-Toe |
A6 - Security Misconfiguration | PHP | Vulnerable Wordpress Misconfig |
A6 - Security Misconfiguration | NodeJS | Stegonography |
A7 - Cross-Site Scripting (XSS) | Python | Gossip World |
A7 - Cross-Site Scripting (XSS) | React | Comment Killer |
A7 - Cross-Site Scripting (XSS) | Angular/Spring | Streaming |
A8 - Insecure Deserialization | Python | Amarelo Designs |
A9 - Using Components With Known Vulnerabilities | PHP | Cimentech |
A10 - Insufficient Logging & Monitoring | Python | GamesIrados.com |
Disclaimer: You are about to install vulnerable mobile apps in your machine! 🔥
Vulnerability | Language | Application |
---|---|---|
M2 - Insecure Data Storage | Dart/Flutter | Cool Games |
M4 - Insecure Authentication | Dart/Flutter | Note Box |
M5 - Insufficient Cryptography | Dart/Flutter | Panda Zap |