awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
portswigger avatar

portswigger/http-request-smuggler

0
View on GitHub↗
1,213 stars·127 forks·Java·8 viewsportswigger.net/blog/http-desync-attacks↗

Http Request Smuggler

This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

Features

  • HTTP Traffic Analysis - Tool for launching HTTP Request Smuggling attacks.
  • Burp Suite Extensions - Automated detection of HTTP request smuggling vulnerabilities.
  • HTTP Request Smuggling - Burp Suite extension for launching HTTP request smuggling attacks.
  • Vulnerability Scanners - Facilitates the execution of HTTP request smuggling attacks.
  • Proxy Tool Extensions - Detect and exploit HTTP request smuggling vulnerabilities.

Star history

Star history chart for portswigger/http-request-smugglerStar history chart for portswigger/http-request-smuggler

How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Http Request Smuggler

Similar open-source projects, ranked by how many features they share with Http Request Smuggler.
  • secdec/attack-surface-detector-burpsecdec avatar

    secdec/attack-surface-detector-burp

    113View on GitHub↗

    The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters

    Java
    View on GitHub↗113
  • portswigger/collaborator-everywherePortSwigger avatar

    PortSwigger/collaborator-everywhere

    447View on GitHub↗

    A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator

    Java
    View on GitHub↗447
  • gosecure/csp-auditorGoSecure avatar

    GoSecure/csp-auditor

    142View on GitHub↗

    Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website

    Java
    View on GitHub↗142
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
See all 30 alternatives to Http Request Smuggler→

Frequently asked questions

What does portswigger/http-request-smuggler do?

This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…

What are the main features of portswigger/http-request-smuggler?

The main features of portswigger/http-request-smuggler are: HTTP Traffic Analysis, Burp Suite Extensions, HTTP Request Smuggling, Vulnerability Scanners, Proxy Tool Extensions.

What are some open-source alternatives to portswigger/http-request-smuggler?

Open-source alternatives to portswigger/http-request-smuggler include: portswigger/collaborator-everywhere — A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal… secdec/attack-surface-detector-burp — The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying… gosecure/csp-auditor — Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… augustd/burp-suite-gwt-scan — Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests. bit4woo/knife — A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅.