afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify
Patator is a multi-purpose brute force tool and modular security framework used for testing credentials, discovering network services, and fuzzing network protocols through automated payload delivery. It functions as a credential exhaustion framework and a network protocol fuzzer. The project provides specific utilities for recovering passwords from encrypted ZIP archives, enumerating DNS zones via forward and reverse queries, and identifying valid usernames and passwords across common network protocols. Its broader capabilities include web endpoint fuzzing, network service probing, and user
AFLNet: A Greybox Fuzzer for Network Protocols (https://thuanpv.github.io/publications/AFLNet_ICST20.pdf)
الميزات الرئيسية لـ aflnet/aflnet هي: Network Protocol Fuzzers.
تشمل البدائل مفتوحة المصدر لـ aflnet/aflnet: lanjelot/patator — Patator is a multi-purpose brute force tool and modular security framework used for testing credentials, discovering… zan8in/afrog — afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and… dobin/ffw — A fuzzing framework for network servers. hgascon/pulsar — Protocol Learning and Stateful Fuzzing. jdbirdwell/afl — american fuzzy lop for network fuzzing (unofficial) -- official afl site is http://lcamtuf.coredump.cx/afl/. cisco-talos/mutiny-fuzzer — Blog post here: * http://blog.talosintelligence.com/2018/01/tutorial-mutiny-fuzzing-framework-and.html.