4 repository-uri
Testing for vulnerabilities in application interfaces and token-based authentication systems.
Distinct from API Token Validators: None of the candidates cover the broad domain of API security testing including both tokens and resource policies.
Explore 4 awesome GitHub repositories matching security & cryptography · API Security Testing. Refine with filters or upvote what's useful.
Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit
Enables probing of server endpoints for security weaknesses via manual request editing.
apk-mitm este un utilitar CLI conceput pentru a modifica fișierele APK de Android, permițând inspectarea traficului HTTPS printr-un proxy. Acesta funcționează ca un instrument de patch pentru securitatea rețelei și de bypass pentru certificate pinning, automatizând procesul de alterare a pachetelor aplicațiilor pentru a permite analiza traficului de tip man-in-the-middle. Instrumentul modifică pachetele Android compilate prin despachetarea lor, alterarea fișierelor interne și re-codarea binarului. Se concentrează în mod specific pe dezactivarea certificate pinning-ului și injectarea configurațiilor de securitate a rețelei în manifestul aplicației, ceea ce permite utilizarea certificatelor proxy atât pe dispozitive cu root, cât și pe cele fără root. Software-ul acoperă testarea securității API-urilor mobile și ingineria inversă prin patch-uri la nivel de bytecode. Include un mecanism pentru a întrerupe procesul de patch, permițând modificarea manuală a fișierelor într-un director temporar înainte ca pachetul final să fie reconstruit și semnat.
Facilitates the interception of encrypted requests to analyze mobile API endpoints and data formats.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Includes a dedicated API security testing manual focusing on JWTs and resource sharing policies.
Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints
Provides a specialized system for testing REST API endpoints for security vulnerabilities and flaws.