tiscripts

Request smuggler scripts

Tools for generating custom request smuggling payloads to exploit vulnerabilities in web applications.

Turbo Intruder Scripts

GitHub

215 stars
6 watching
57 forks
Language: Python
last commit: over 4 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
defparam/smuggler An HTTP Request Smuggling / Desync testing tool written in Python 3 1,819
anshumanpattnaik/http-request-smuggling Detects HTTP Request Smuggling vulnerabilities in web applications 472
portswigger/http-request-smuggler An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities. 958
nachiketrathod/http.request.smuggling.desync.attack An attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls. 14
swisskyrepo/payloadsallthethings A comprehensive collection of tools and techniques for web application security testing and exploitation 61,485
amirnsahmad/smuggler A tool for testing HTTP request smuggling and desync issues in web servers. 13
freefv/tencent_yun_tools A collection of Python scripts to exploit vulnerabilities in Tencent Cloud services using an AccessKey 34
portswigger/turbo-intruder A tool for sending and analyzing large numbers of HTTP requests to test web application security vulnerabilities. 1,499
portswigger/crypto-attacker A collection of tools and scripts for penetration testing and vulnerability assessment of web applications. 2
0ang3el/websocket-smuggle A tool to expose security vulnerabilities in WebSocket reverse proxying allowing HTTP requests to be smuggled through 337
detectify/varnish-h2-request-smuggling A Docker-based test environment for simulating a Varnish HTTP/2 request smuggling vulnerability 55
virustotal/vt-ida-plugin An IDA Pro plugin that searches for similar code, strings, or sequences of bytes using VirusTotal's web services. 155
1n3/intruderpayloads A collection of tools and methodologies for web application testing and vulnerability assessment. 3,686
bishopfox/h2csmuggler Smuggling HTTP traffic past proxy rules to bypass access controls 650
quentinhardy/scriptsandexploits Exploits a known vulnerability in Oracle WebLogic to execute arbitrary code 142