10 个仓库
Extensions for testing authorization and authentication mechanisms.
Explore 10 awesome GitHub repositories matching part of an awesome list · Authentication Testing. Refine with filters or upvote what's useful.
Hydra is a network login password cracker and authentication tester designed to identify valid usernames and passwords through automated brute-force and dictionary attacks. It serves as a multi-protocol authentication tester capable of verifying credentials across a wide range of remote network services, including SSH, SMB, FTP, and various database listeners. The project is distinguished by its ability to execute parallelized password attacks against multiple servers and protocols simultaneously. It features a modular system for implementing diverse network authentication schemes, allowing f
Automates login attempts across various network protocols to test the strength of remote service passwords.
This project is a collection of patterns and configurations for deploying AI agents with specialized technical skills and personas. It provides a framework for agentic software engineering, defining standards for AI-driven development workflows and the management of modular technical capabilities. The system features a skill framework that activates technical guidelines based on prompt intent and a context management system that preserves project state using persistent plans and checklists across session resets. It employs a modular organization of guidelines to prevent context window overflo
Provides utilities for validating API route functionality using token-based authentication to debug access errors.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Evaluates registration, password policies, and multi-factor authentication to identify identity management flaws.
This project is a transparent proxy framework designed for the interception, analysis, and manipulation of secure shell traffic. By terminating client and server connections independently, it provides full visibility into encrypted sessions, allowing for the monitoring of authentication flows, file transfers, and command execution in real time. The tool distinguishes itself through a modular, plugin-based architecture that enables users to inject custom interception logic into the proxy workflow. It supports the creation of ephemeral environments and mock agents in memory, facilitating the si
Probes remote servers and simulates client responses to evaluate the robustness of authentication methods and multi-factor security.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
Automates the detection of authorization enforcement flaws.
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
Provides a framework for testing authorization across user roles.
Released as open source by NCC Group Plc - http://www.nccgroup.trust/
Performs Kerberos authentication testing.
Burp plugin to test for authorization flaws
Tests for authorization flaws in web applications.
Burp extension to specify the token value for the Authenication header while scanning.
Updates authentication tokens dynamically during scanning.
Extension for Burp Suite - to be used via Session Handling Rules.
Tests authorization specifically for AMX-based applications.