10 dépôts
Extensions for testing authorization and authentication mechanisms.
Explore 10 awesome GitHub repositories matching part of an awesome list · Authentication Testing. Refine with filters or upvote what's useful.
Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f
Automates login attempts across various network protocols to test the strength of remote service passwords.
This project is a collection of patterns and configurations for deploying AI agents with specialized technical skills and personas. It provides a framework for agentic software engineering, defining standards for AI-driven development workflows and the management of modular technical capabilities. The system features a skill framework that activates technical guidelines based on prompt intent and a context management system that preserves project state using persistent plans and checklists across session resets. It employs a modular organization of guidelines to prevent context window overflo
Provides utilities for validating API route functionality using token-based authentication to debug access errors.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Evaluates registration, password policies, and multi-factor authentication to identify identity management flaws.
Ce projet est un framework de proxy transparent conçu pour l'interception, l'analyse et la manipulation du trafic SSH. En terminant les connexions client et serveur indépendamment, il offre une visibilité totale sur les sessions chiffrées, permettant de surveiller les flux d'authentification, les transferts de fichiers et l'exécution de commandes en temps réel. L'outil se distingue par une architecture modulaire basée sur des plugins qui permet aux utilisateurs d'injecter une logique d'interception personnalisée dans le flux du proxy. Il prend en charge la création d'environnements éphémères et d'agents fictifs en mémoire, facilitant la simulation de scénarios de sécurité et le test de la robustesse de l'authentification sans nécessiter d'infrastructure externe. Le framework couvre une large surface de capacités, incluant l'audit du comportement de sécurité des clients, la capture d'identifiants d'authentification et l'inspection de protocoles réseau encapsulés tels que les tunnels et les opérations de gestion à distance. Il fournit également des contrôles opérationnels pour gérer les sessions simultanées et maintenir la parité de session via le transfert de signaux de terminal.
Probes remote servers and simulates client responses to evaluate the robustness of authentication methods and multi-factor security.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Automates the detection of authorization enforcement flaws.
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
Provides a framework for testing authorization across user roles.
Released as open source by NCC Group Plc - http://www.nccgroup.trust/
Performs Kerberos authentication testing.
Burp plugin to test for authorization flaws
Tests for authorization flaws in web applications.
Burp extension to specify the token value for the Authenication header while scanning.
Updates authentication tokens dynamically during scanning.
Extension for Burp Suite - to be used via Session Handling Rules.
Tests authorization specifically for AMX-based applications.