Releases: RIZZZIOM/FlawFactory
Releases · RIZZZIOM/FlawFactory
v1.0
Vulnerability Modules (9)
- Command injection
- XSS
- Insecure deserialization
- IDOR
- No-SQL injection
- Path traversal
- SSRF
- SQL injection
- XXE
Input Placements (7)
- URL query string
- URL path segment
- POST form data
- JSON body field
- HTTP header
- Cookie value
- Multipart form field
Sinks (4)
- SQLite
- Filesystem
- Command
- HTTP
Configuration
- YAML-based declarative configuration
- Pre-built vulnerability templates
- Configuration validation with detailed errors/warnings
- 4 response types: JSON, HTML, Template, File
CLI
run- Start vulnerable servervalidate- Validate config without startingmodules- List available modules
Server
- HTTP and HTTPS support
- JSON request logging
- Graceful shutdown
- Port override via CLI