http-request-smuggling
Smuggling detector
Detects HTTP Request Smuggling vulnerabilities in web applications
HTTP Request Smuggling Detection Tool
476 stars
8 watching
101 forks
Language: Python
last commit: about 1 year ago
Linked from 1 awesome list
blackhatchunked-encodingcontent-lengthdefcon27desync-attackhttp-request-smugglingportswiggerpython3smugglingtransfer-encoding
Related projects:
Repository | Description | Stars |
---|---|---|
| An attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls. | 14 |
| An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities. | 964 |
| An HTTP Request Smuggling / Desync testing tool written in Python 3 | 1,840 |
| A tool for testing HTTP request smuggling and desync issues in web servers. | 13 |
| Smuggling HTTP traffic past proxy rules to bypass access controls | 661 |
| A Docker-based test environment for simulating a Varnish HTTP/2 request smuggling vulnerability | 55 |
| Tools for generating custom request smuggling payloads to exploit vulnerabilities in web applications. | 218 |
| A tool to expose security vulnerabilities in WebSocket reverse proxying allowing HTTP requests to be smuggled through | 341 |
| A set of BurpSuite extensions for pentesting and testing | 10 |
| A lightweight Python HTTP library for analyzing and interacting with web servers | 466 |
| Tools for detecting phishing websites by analyzing favicon hashes and searching on Shodan | 115 |
| A tool for stealthy data transfer using DNS queries and text-based steganography to evade attribution and detection. | 624 |
| Tools to help identify vulnerabilities in web applications using HTTPoxy scanning. | 90 |
| An asynchronous HTTP client with TLS and fingerprint spoofing capabilities | 112 |
| Analyzes web-based network traffic to detect malicious command and control servers using Squid proxy server and Spamhaus | 78 |