http-request-smuggler
by PortSwigger
AI summary
Request Smuggling Tool
An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities.
- stars
- 964
- forks
- 103
- watching
- 27
Similar projects
Found by comparing what the projects do, not just their names.
Smuggling detector
Detects HTTP Request Smuggling vulnerabilities in web applications
Vulnerability scanner
Tools to help identify vulnerabilities in web applications using HTTPoxy scanning.
Vulnerability scanner
An extension for Burp Suite that scans for unknown classes of injection vulnerabilities using a novel approach
Pentesting suite extensions
A set of BurpSuite extensions for pentesting and testing
Test replication tool
An extension for the Burp Suite toolset to help developers reproduce issues discovered by pen testers
Parameter detective
An extension tool used to identify hidden parameters in web requests
Parameter vulnerability exploit toolkit
Tools and techniques for exploiting reflected parameter vulnerabilities in Java-based applications
Request copier
A plugin that allows Burp Suite users to easily copy selected requests as Python code
Scanning toolkit
A Java-based toolset that provides custom scanning checks and techniques for extending Burp Suite's built-in scanning capabilities.
Vulnerability scanner
An OS command injection detection and exploitation tool that provides methodologies and software for identifying and exploiting vulnerabilities in applications.
IP address generator
This Java project generates and manipulates HTTP headers to include random IP addresses for testing and development purposes.
Web vulnerability scanner
A collection of passive scanner checks to identify security vulnerabilities in web applications
Web application security scanner
An HTML validation and security testing tool for identifying vulnerabilities in web applications
Desync tester
An HTTP Request Smuggling / Desync testing tool written in Python 3
Request Smuggling Attack
An attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls.