http-request-smuggler

Request Smuggling Tool

An extension for Burp Suite to help identify and exploit HTTP Request Smuggling vulnerabilities.

GitHub

964 stars
27 watching
103 forks
Language: Java
last commit: almost 3 years ago

Related projects:

RepositoryDescriptionStars
anshumanpattnaik/http-request-smugglingDetects HTTP Request Smuggling vulnerabilities in web applications476
portswigger/httpoxy-scannerTools to help identify vulnerabilities in web applications using HTTPoxy scanning.90
portswigger/backslash-powered-scannerAn extension for Burp Suite that scans for unknown classes of injection vulnerabilities using a novel approach643
portswigger/json-decoderA set of BurpSuite extensions for pentesting and testing10
portswigger/replicatorAn extension for the Burp Suite toolset to help developers reproduce issues discovered by pen testers70
portswigger/param-minerAn extension tool used to identify hidden parameters in web requests1,273
portswigger/reflected-parametersTools and techniques for exploiting reflected parameter vulnerabilities in Java-based applications19
portswigger/copy-as-python-requestsA plugin that allows Burp Suite users to easily copy selected requests as Python code62
portswigger/example-scanner-checksA Java-based toolset that provides custom scanning checks and techniques for extending Burp Suite's built-in scanning capabilities.15
portswigger/command-injection-attackerAn OS command injection detection and exploitation tool that provides methodologies and software for identifying and exploiting vulnerabilities in applications.106
portswigger/random-ip-address-headerThis Java project generates and manipulates HTTP headers to include random IP addresses for testing and development purposes.6
portswigger/additional-scanner-checksA collection of passive scanner checks to identify security vulnerabilities in web applications27
portswigger/html5-auditorAn HTML validation and security testing tool for identifying vulnerabilities in web applications4
defparam/smugglerAn HTTP Request Smuggling / Desync testing tool written in Python 31,840
nachiketrathod/http.request.smuggling.desync.attackAn attacker exploits HTTP request smuggling to manipulate the sequence of requests and deceive both front-end and back-end security controls.14