How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator
Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website
w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing
This Burp Suite extension automatically detects and exploits HTTP Request Smuggling vulnerabilities using advanced desynchronization techniques developed by PortSwigger researcher James Kettle. It supports comprehensive scanning for HTTP/1.1 and HTTP/2-downgrade desync vulnerabilities,…
The main features of portswigger/http-request-smuggler are: HTTP Traffic Analysis, Burp Suite Extensions, HTTP Request Smuggling, Vulnerability Scanners, Proxy Tool Extensions.
Open-source alternatives to portswigger/http-request-smuggler include: portswigger/collaborator-everywhere — A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal… secdec/attack-surface-detector-burp — The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying… gosecure/csp-auditor — Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… augustd/burp-suite-gwt-scan — Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests. bit4woo/knife — A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅.