awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

10 repositorios

Awesome GitHub RepositoriesSession Hijacking

Techniques for intercepting and reusing valid authentication session tokens to bypass multi-factor authentication.

Distinct from Authentication Bypass Techniques: Distinct from Authentication Bypass Techniques: focuses specifically on session token theft and reuse rather than general input manipulation or logic flaws.

Explore 10 awesome GitHub repositories matching security & cryptography · Session Hijacking. Refine with filters or upvote what's useful.

Awesome Session Hijacking GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • nesquena/hermes-webuiAvatar de nesquena

    nesquena/hermes-webui

    14,912Ver en GitHub↗

    Hermes-webui is a self-hosted AI orchestrator and web interface for managing autonomous agents. It serves as a multi-provider gateway that connects cloud and local large language models, providing a central hub to execute scheduled background jobs, run shell commands, and manage agent memory on private hardware. The system distinguishes itself through a persistent memory manager that utilizes knowledge graphs and markdown files for long-term context across sessions. It features a model context protocol host for extending agent capabilities with standardized tools and supports the orchestratio

    Allows agent tools to attach to a running local browser instance to leverage existing cookies and sessions.

    Pythonagentai-agentshermes
    Ver en GitHub↗14,912
  • kgretzky/evilginx2Avatar de kgretzky

    kgretzky/evilginx2

    14,627Ver en GitHub↗

    Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte

    Implements session hijacking to bypass multi-factor authentication by capturing and reusing valid authentication cookies.

    Go
    Ver en GitHub↗14,627
  • daffainfo/allaboutbugbountyAvatar de daffainfo

    daffainfo/AllAboutBugBounty

    6,644Ver en GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Documents session persistence bypass techniques for maintaining access after 2FA is enabled.

    bugbugbountybugbountytips
    Ver en GitHub↗6,644
  • victornpb/undiscordAvatar de victornpb

    victornpb/undiscord

    6,583Ver en GitHub↗

    Undiscord is a browser-based tool that deletes all messages from a Discord channel or direct message conversation by running a self-contained JavaScript snippet in the developer console. The script leverages the user's existing browser session, including cookies and authentication tokens, to impersonate the user and execute Discord API calls without re-authentication. The tool deletes messages one by one via Discord's REST API endpoints, processing each response before sending the next request, and implements custom delay logic between API calls to avoid Discord's rate-limiting thresholds. It

    Leverages existing browser cookies and authentication tokens to impersonate the user for Discord API requests without re-authentication.

    JavaScriptbrowser-extensionbulk-operationdelete-multiple
    Ver en GitHub↗6,583
  • epiral/bb-browserAvatar de epiral

    epiral/bb-browser

    5,814Ver en GitHub↗

    bb-browser is an authenticated web scraper and browser automation CLI that also functions as an MCP server for AI coding tools. It treats the browser as a programmable runtime environment, enabling AI agents to control a live Chrome instance through a standard protocol while leveraging existing login sessions for authenticated actions. The project distinguishes itself through a dual CLI and MCP interface, allowing both direct command-line control and AI-driven browser manipulation. It includes a parallel multi-platform query engine that executes simultaneous searches across multiple websites,

    Leverages existing browser login sessions to perform authenticated actions without re-entering credentials.

    TypeScript
    Ver en GitHub↗5,814
  • browsermcp/mcpAvatar de BrowserMCP

    BrowserMCP/mcp

    5,817Ver en GitHub↗

    BrowserMCP is a browser automation bridge that connects AI tools to a live browser session through a local proxy server. It implements a standardized protocol for sending commands like click, type, and navigate to a real browser instance running on the user's machine, while keeping all browsing data on the device. The project distinguishes itself by preserving user sessions and fingerprints across automation tasks. It attaches to the user's existing browser profile to maintain cookies, logins, and authentication state, and uses the real browser's user agent, viewport, and extension context to

    Reuses existing browser session tokens and cookies to preserve authentication across automation tasks.

    TypeScriptbrowser-automationbrowser-extensionclaude
    Ver en GitHub↗5,817
  • projectdiscovery/naabuAvatar de projectdiscovery

    projectdiscovery/naabu

    5,766Ver en GitHub↗

    Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet

    Attaches to a running Chrome instance with remote debugging to reuse an existing authenticated session for crawling.

    Gocdn-exclusionhacktoberfestnmap
    Ver en GitHub↗5,766
  • browser-use/workflow-useAvatar de browser-use

    browser-use/workflow-use

    4,054Ver en GitHub↗

    Este proyecto es un framework de automatización de navegador para LLM y una interfaz de navegador para agentes de IA. Sirve como una capa de control que traduce instrucciones en lenguaje natural en interacciones de navegador utilizando modelos de lenguaje grandes, permitiendo a los agentes de IA navegar e interactuar con páginas web a través de funciones de control de navegador estandarizadas. El sistema funciona como un orquestador de flujos de trabajo RPA y una herramienta de gestión de navegador headless, capaz de grabar y reproducir secuencias de navegador deterministas para automatizar tareas repetitivas. Se distingue por configuraciones de sigilo, incluyendo proxies residenciales y motores de navegador modificados, para evitar la detección de bots y resolver CAPTCHAs. La plataforma cubre una amplia gama de capacidades, incluyendo la extracción estructurada de datos web, la gestión de sesiones persistentes para mantener la autenticación y la intervención humana (human-in-the-loop) para pasos complejos como la autenticación de múltiples factores. Admite tanto la conectividad local como despliegues en sandbox en la nube gestionados, ofreciendo gestión visual de flujos de trabajo y monitoreo de actividad en tiempo real a través de gráficos interactivos. La integración se proporciona a través de una interfaz de línea de comandos y conectividad API para proveedores de LLM externos y plataformas de orquestación de terceros.

    Attaches to existing running browser instances via remote debugging to preserve active tabs and authenticated sessions.

    Pythonbrowser-automationbrowser-use-boxrpa
    Ver en GitHub↗4,054
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Ver en GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Captures active session cookies to impersonate authenticated users.

    Shellhackhackinghacking-tool
    Ver en GitHub↗3,020
  • specterops/bloodhoundAvatar de SpecterOps

    SpecterOps/BloodHound

    2,789Ver en GitHub↗

    BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij

    Implements a reverse proxy to stream live browser sessions and bypass multi-factor authentication.

    Go
    Ver en GitHub↗2,789
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Authentication Bypass Techniques
  7. Session Hijacking

Explorar subetiquetas

  • Browser Session Token Reuse1 sub-etiquetaLeveraging existing browser cookies and authentication tokens to impersonate a user for API requests without re-authentication. **Distinct from Session Hijacking:** Distinct from Session Hijacking: focuses on reusing existing browser session tokens for API calls rather than intercepting or stealing tokens from network traffic.
  • Session Persistence BypassesKeeps authenticated sessions active after security changes to circumvent new authentication requirements. **Distinct from Session Hijacking:** Distinct from Session Hijacking: focuses on maintaining existing sessions after 2FA is enabled, not stealing tokens.