24 repositorios
Processes for inspecting and validating protocol headers and origins during connection establishment.
Distinct from Handshake Protocols: Focuses on request validation (headers/origins) specifically, rather than the cryptographic key exchange of general handshake protocols.
Explore 24 awesome GitHub repositories matching security & cryptography · Handshake Validations. Refine with filters or upvote what's useful.
This project is a Node.js WebSocket library that provides a high-performance client and server implementation for the WebSocket protocol. It functions as a transport layer for real-time bidirectional communication, supporting both UTF-8 strings and binary data transport through the use of TCP socket wrappers. The library enables the creation of WebSocket servers that manage full-duplex connections and broadcast messages to multiple clients, as well as WebSocket clients that establish persistent links to remote servers. It handles the protocol upgrade process via TCP-based handshake negotiatio
Inspects request headers and origins during the protocol upgrade to accept or reject connections.
Este proyecto es una herramienta de verificación de correo electrónico que comprueba si una dirección de correo electrónico existe y puede recibir mensajes sin enviar un correo electrónico real. Proporciona estas capacidades a través de una API HTTP programable y una interfaz de línea de comandos local. El sistema se distingue por combinar la verificación de saludo SMTP y la resolución de registros DNS con una herramienta de análisis de riesgos que detecta direcciones desechables, cuentas basadas en roles y dominios catch-all. También incluye un agregador de metadatos para recuperar información de perfil público e imágenes asociadas con una dirección de correo electrónico específica. La superficie de capacidad más amplia cubre la validación de entregabilidad de correo electrónico, la evaluación de riesgos para prevenir registros fraudulentos y las pruebas de conectividad SMTP. El servicio de backend puede desplegarse como un servicio en red utilizando un modelo de despliegue en contenedores.
Verifies email reachability and mailbox existence using the SMTP protocol handshake and DNS record resolution.
Websocat is a specialized set of command-line tools for WebSocket communication, acting as a client, server, and stream processor. It provides a terminal-based interface for connecting to WebSocket servers, hosting secure WebSocket servers, and bridging data between WebSockets and other network transports. The project distinguishes itself by functioning as a bidirectional network relay, allowing the routing of data between WebSocket streams, TCP sockets, UNIX sockets, and standard system input and output. It includes specialized implementations for SOCKS5 and HTTP proxying, as well as a strea
Wraps raw socket connections with TLS using PKCS#12 certificates for secure communication.
This project is a self-hosted email verification system and API designed to validate email existence and clean mailing lists on private infrastructure. It functions as a deliverability tool that confirms if email addresses are reachable by communicating with mail servers via the SMTP protocol without sending actual messages. The system is distinguished by its high-volume SMTP infrastructure, which utilizes a stateless worker architecture and message queue task distribution to scale validation tasks. It includes an SMTP proxy gateway that routes requests through SOCKS5 proxies to mask server i
Validates email existence by simulating the SMTP mail transfer protocol exchange without sending a full message.
Mbed TLS is an open-source TLS and DTLS library with a small footprint, designed for embedded systems and IoT devices. It provides a portable cryptographic library that includes symmetric ciphers, hashing, and public-key cryptography, along with a reference implementation of the PSA Cryptography API for standardized cryptographic operations across platforms. The library also offers X.509 certificate management for parsing, validating, and managing certificate chains in secure communications. The library is built around a platform abstraction layer that decouples it from OS-specific services t
Provides a configuration option to skip certificate expiration checks when no real-time clock is available.
An HTTP proxy library for Go
Generates per-host TLS certificates on the fly during the TLS handshake for HTTPS interception.
Hazelcast is a distributed data platform that combines an in-memory data grid with a stream processing engine to support real-time analytics and event-driven applications. It functions as a partitioned, distributed key-value store that replicates data across cluster nodes to provide low-latency access and high availability. The platform also serves as a distributed SQL query engine, allowing users to execute standard SQL statements against both in-memory datasets and external data sources. What distinguishes Hazelcast is its use of a distributed consensus subsystem to maintain strongly consis
Verifies that server hostnames match X.509 certificates during TLS handshakes to prevent man-in-the-middle attacks.
Microsandbox is a runtime for creating and managing lightweight, hardware-isolated virtual machines — called sandboxes — that boot directly from standard OCI container images. Each sandbox runs as its own host process with a separate kernel, filesystem, and network stack, providing process-per-sandbox isolation. The project includes a command-line tool and multi-language SDKs (Rust, TypeScript, Python, Go) for programmatic lifecycle control, and it communicates with sandbox agents over Unix sockets using a CBOR-encoded protocol. What distinguishes Microsandbox is its combination of host-manag
Returns cached handshake frame data as raw CBOR bytes without generating additional protocol traffic.
GmSSL is an open-source cryptographic library that implements the Chinese national cryptographic standards SM2, SM3, SM4, SM9, and ZUC as a unified algorithm suite. It provides a comprehensive set of cryptographic primitives including symmetric and asymmetric encryption, digital signatures, hashing, and key exchange, all built around these national standards for government and enterprise security applications. The library distinguishes itself through several integration capabilities. It includes an OpenSSL compatibility layer that maps GmSSL functions to OpenSSL API calls, enabling drop-in re
Check that a server's certificate matches the expected hostname, supporting wildcard matching to prevent man-in-the-middle attacks.
Maddy is a modular mail server that assembles a complete email system by connecting small, single-purpose modules through a declarative configuration file. Rather than a monolithic stack, it lets operators compose message processing, storage, authentication, and security enforcement from interchangeable building blocks, with each module handling a specific function like receiving SMTP connections, verifying credentials, or applying policy checks. The server distinguishes itself through its flexible authentication and security architecture. It delegates user verification to external systems in
Accepts email messages through SMTP, LMTP, or Submission protocols, optionally verifying sender credentials before processing.
CRI-O is an open-source container runtime that implements the Kubernetes Container Runtime Interface (CRI) to manage container images, pods, and containers on cluster nodes using OCI-compatible runtimes. It serves as a node-level container manager that handles image pulling, container lifecycle, and resource monitoring for Kubernetes clusters, running containers according to the Open Container Initiative specifications. The runtime distinguishes itself through live configuration reloading that applies changes to runtime definitions, registry mirrors, and TLS certificates without restarting th
Validates that TLS certificates for the metrics endpoint are within their validity period.
Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each
Provides a two-stage key exchange to establish encrypted communication between agents and the command server.
Este proyecto es un sistema de simulación y mocking de API multiprotocolo diseñado para reemplazar dependencias externas durante el desarrollo y las pruebas. Proporciona un servidor de mocking de API, un proxy de tráfico de red y simuladores especializados para servicios de modelos de lenguaje y proveedores de identidad. El sistema se distingue por sus capacidades de simulación de IA profunda, incluyendo la emulación de proveedores de modelos de lenguaje y servidores de Model Context Protocol usando JSON-RPC 2.0. Soporta lógica conversacional de múltiples turnos, seguimiento de estado para APIs de chat de IA y visualización de la ejecución de agentes mediante grafos de llamadas y seguimiento del uso de tokens. Las áreas de capacidad incluyen pruebas de contrato de API contra especificaciones OpenAPI, resiliencia e ingeniería del caos mediante inyección de fallos de red, e interceptación de tráfico en vivo para la modificación de solicitudes en tiempo real. El proyecto también gestiona la simulación de proveedores de identidad para los estándares OIDC, OAuth2, SAML 2.0 y SCIM 2.0. El servidor puede desplegarse como un contenedor Docker, mediante Helm charts de Kubernetes o como un binario nativo independiente.
The tool accepts self-signed, expired, or invalid TLS certificates when forwarding requests to remote services.
Covenant es un framework de comando y control basado en .NET diseñado para operaciones de red team y simulación de adversarios. Sirve como plataforma colaborativa para coordinar evaluaciones de seguridad, gestionar implantes remotos y ejecutar tareas en sistemas comprometidos a través de un servidor centralizado. El proyecto se distingue por su generador de payloads dinámico, que compila y ofusca binarios ejecutables y scripts al vuelo para evadir la detección. Se separa aún más a través de un entorno colaborativo que permite a múltiples operadores autenticados compartir un estado sincronizado, rastrear indicadores operativos y gestionar compromisos conjuntos dentro de una única interfaz. El framework proporciona capacidades extensas para la ofuscación de tráfico, incluyendo el uso de perfiles de red personalizados, pipelines de transformación de datos y traducción de protocolos basada en puentes para enmascarar comunicaciones. También cubre necesidades de post-explotación como recuperación remota de archivos, recolección centralizada de credenciales y el desarrollo de módulos de tareas remotas personalizados utilizando un modelo de extensión de plug-in. El sistema asegura las comunicaciones entre el servidor y los agentes utilizando pinning de certificados SSL e intercambios de claves cifrados para asegurar el secreto hacia adelante (forward secrecy).
Implements encrypted key exchanges during the initial handshake to ensure forward secrecy between agents and the server.
Websockify es un proxy WebSocket-a-TCP y servidor de túnel que permite a los navegadores web comunicarse con servidores o aplicaciones que solo admiten conexiones TCP estándar. Funciona como un puente de red y broker de conexiones, traduciendo tramas WebSocket bidireccionales en paquetes TCP crudos para facilitar el acceso remoto del navegador a servicios de backend. El sistema actúa como una pasarela de sockets segura que admite enrutamiento de sockets multi-inquilino, permitiendo que múltiples clientes sean dirigidos a diferentes destinos de backend basados en tokens de URL únicos o nombres de host. Asegura los datos en tránsito envolviendo las conexiones en cifrado SSL/TLS y utiliza un sistema basado en plugins para autenticar a los usuarios antes de establecer conexiones de backend. Las capacidades adicionales incluyen un modelo de trabajador multiproceso para escalar cargas de conexión concurrentes y la capacidad de interceptar procesos locales para redirigir la salida de red al flujo del proxy. El proyecto también proporciona herramientas para grabar flujos de bytes de red crudos para depuración y puede servir contenido web estático desde un directorio local en el mismo puerto que el proxy. El software puede operarse como un demonio para mantener una conectividad persistente sin una sesión de terminal activa.
Wraps raw socket traffic in an SSL/TLS encrypted layer using certificates to secure data in transit.
This project is a DNS privacy proxy and resolver that functions as a local bridge, converting plaintext DNS traffic into encrypted requests. It acts as a client for DNS-over-HTTPS and DNS-over-TLS protocols to prevent interception and spoofing of network requests. The system implements network privacy hardening by routing domain lookups through secure tunnels, which reduces the amount of plain text data leaked to internet service providers. It utilizes a profile-based connection management system to map security profiles to specific encrypted endpoints, preventing DNS hijacking and man-in-the
Validates server certificates during TLS handshake to prevent man-in-the-middle attacks.
Synapse es una implementación de homeserver de Matrix que proporciona la infraestructura para la comunicación y mensajería descentralizada en tiempo real. Funciona como un servidor de chat federado que sincroniza datos de salas y flujos de eventos a través de instancias de servidor independientes para permitir la interoperabilidad entre dominios. El servidor utiliza un núcleo híbrido que integra lógica crítica para el rendimiento en Rust con una capa de orquestación en Python. Emplea una base de datos relacional PostgreSQL para persistir cuentas de usuario e historial de conversaciones, y utiliza un sistema de mensajería basado en Redis para distribuir tareas entre trabajadores horizontales. El proyecto cubre una amplia gama de capacidades, incluyendo gestión de identidad segura con integración SAML y OpenID Connect, herramientas administrativas integrales para la moderación de contenido y gestión de salas, y manejo automatizado de medios. También incluye sistemas para federación descentralizada, migración asíncrona de esquemas de base de datos y exportación de telemetría para el monitoreo del rendimiento.
Enforces certificate verification during the TLS handshake for the federation API to prevent man-in-the-middle attacks.
Endless es un wrapper de servidor y gestor de procesos sin tiempo de inactividad (zero-downtime) para servidores HTTP en Go. Reemplaza los listeners de la librería estándar para coordinar las transiciones de procesos y la gestión de sockets, permitiendo que los binarios se actualicen sin soltar las conexiones de red activas. El proyecto permite reinicios sin tiempo de inactividad bifurcando un nuevo proceso hijo para hacerse cargo de los sockets de red antes de que el proceso padre se cierre. Gestiona el flujo de tráfico seguro envolviendo los servidores con capas de cifrado TLS y admite la coordinación tanto para puertos de red estándar como para sockets Unix. El sistema maneja el ciclo de vida del servidor a través de la gestión basada en señales, ejecutando funciones específicas de configuración y limpieza durante los reinicios. Garantiza la disponibilidad continua mediante la coordinación de traspaso de sockets y proporciona mecanismos de apagado elegante que drenan las solicitudes activas o terminan las conexiones colgantes después de un período de gracia definido.
Wraps standard HTTP servers with TLS encryption layers while preserving the ability to perform process rotations.
urllib3 is a Python HTTP client library used to send network requests and receive responses. It provides core components for managing HTTP connection pools, routing traffic through proxies, validating TLS certificates, and executing automatic request retries. The library focuses on network reliability and efficiency by maintaining a system that reuses established connections to multiple hosts to reduce latency. It ensures secure communication through client-side certificate verification and handles transient network errors using policy-based retry logic. The project covers broad networking c
Validates server certificates during the TLS handshake to prevent man-in-the-middle attacks.
urllib3 is a Python HTTP client library used for sending network requests and receiving responses. It functions as an HTTP connection pool manager and a TLS certificate validator to ensure secure communication between endpoints. The library provides a system for maintaining reusable network connections to reduce the overhead of repeated handshakes. It also serves as an HTTP proxy client capable of routing requests through proxy servers to manage origin identity or bypass firewalls. The tool covers programmatic file uploads via multipart encoding and automated network resilience through the u
Verifies server identity during the TLS handshake to prevent man-in-the-middle attacks.