4 个仓库
Testing for vulnerabilities in application interfaces and token-based authentication systems.
Distinct from API Token Validators: None of the candidates cover the broad domain of API security testing including both tokens and resource policies.
Explore 4 awesome GitHub repositories matching security & cryptography · API Security Testing. Refine with filters or upvote what's useful.
Hetty is an HTTP intercepting proxy and web security research toolkit used to capture, inspect, and modify traffic between a browser and a server. It functions as an HTTP request editor for creating and replaying manual requests to test server behavior and as a project-based traffic logger that isolates network logs across different security research engagements. The tool provides a request-response interception loop that pauses outgoing requests and incoming responses in transit, allowing for manual editing or cancellation. It includes a manual request replay engine to construct and transmit
Enables probing of server endpoints for security weaknesses via manual request editing.
apk-mitm 是一个命令行实用程序,旨在修改 Android APK 文件以通过代理进行 HTTPS 流量检查。它充当网络安全补丁工具和证书锁定绕过工具,通过自动化修改应用程序包来允许中间人流量分析。 该工具通过解包、修改内部文件并重新编码二进制文件来修改已编译的 Android 包。它专注于禁用证书锁定并将网络安全配置注入应用程序清单,从而允许在已 root 和未 root 的设备上使用代理证书。 该软件涵盖了移动 API 安全测试和通过字节码级补丁进行的逆向工程。它包含一个暂停补丁过程的机制,允许在重建和签名最终包之前在临时目录中进行手动文件修改。
Facilitates the interception of encrypted requests to analyze mobile API endpoints and data formats.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Includes a dedicated API security testing manual focusing on JWTs and resource sharing policies.
Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints
Provides a specialized system for testing REST API endpoints for security vulnerabilities and flaws.