h2csmuggler
Proxy smuggler
Smuggling HTTP traffic past proxy rules to bypass access controls
HTTP Request Smuggling over HTTP/2 Cleartext (h2c)
661 stars
17 watching
100 forks
Language: Python
last commit: almost 3 years ago
Linked from 2 awesome lists
bugbountyinfosecsecurity-researchsecurity-tools
Related projects:
Repository | Description | Stars |
---|---|---|
| Detects HTTP Request Smuggling vulnerabilities in web applications | 476 |
| An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities. | 964 |
| A Docker-based test environment for simulating a Varnish HTTP/2 request smuggling vulnerability | 55 |
| An HTTP Request Smuggling / Desync testing tool written in Python 3 | 1,840 |
| An anti-censorship HTTP proxy with built-in support for various protocols. | 136 |
| Searches public EBS snapshots for hidden secrets and passwords | 289 |
| A tool to expose security vulnerabilities in WebSocket reverse proxying allowing HTTP requests to be smuggled through | 341 |
| A toolkit for testing and exploiting ZigBee networks to identify vulnerabilities in IoT devices | 265 |
| A low-level HTTP/2 library for exploiting race conditions in web servers | 153 |
| Creates a SOCKS proxy server by chaining vulnerable UPnProxy devices | 82 |
| An attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls. | 14 |
| Utility to decrypt and access decrypted iOS apps on jailbroken devices | 444 |
| An open-source tool to help penetration testers gather information about cloud environments and identify potential vulnerabilities. | 1,983 |
| Tools to convert arguments between cURL and HTTPie protocols | 157 |
| Tunneling tool for SSH through HTTP proxies | 1,142 |