SQLi-Query-Tampering

Payload Generator

Customizable extension for Burp Suite's Intruder to generate and process SQLi payloads with various evasion techniques.

SQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.

GitHub

151 stars
6 watching
23 forks
Language: Python
last commit: about 6 years ago
bug-bountybugbountybughuntingburp-extensionsburp-pluginburpsuiteburpsuite-proevasionpayload-generatorpentestingpentesting-toolssqlisqlinjection

Related projects:

RepositoryDescriptionStars
attackercan/burp-xss-sql-pluginAutomated tool for detecting cross-site scripting (XSS) and SQL injection vulnerabilities in web applications.44
jiangsir404/xss-sql-fuzzAutomates fuzzing of XSS and SQL injection vulnerabilities in web applications using Burp Suite extensions.61
initroot/burpsqltruncsannerAutomatically scans endpoints for potential SQL Truncation vulnerabilities by fuzzing request parameters62
zt2/sqli-hunterA tool that automates the process of detecting and exploiting SQL injection vulnerabilities in web applications.425
ebryx/aes-killerA plugin for Burp Suite to decrypt AES-encrypted traffic on the fly.634
anof-cyber/pycriptA tool for bypassing client-side encryption in web applications during penetration testing and bug bounty activities192
vsec7/burpsuite-xkeysAn extension for Burp Suite to identify and extract interesting strings from web pages251
volkandindar/agarthaAn extension for a web application security testing tool that identifies vulnerabilities and exploits HTTP requests for penetration testing.355
cyal1/pyburpAn extension that allows modifying HTTP requests and responses with Python code to facilitate security testing of encrypted transactions22
aress31/openapi-parserAutomates security assessment of REST APIs using Burp Suite195
xnl-h4ck3r/gap-burp-extensionAn extension for Burp Suite that identifies potential security vulnerabilities in web applications by analyzing endpoints, parameters, and generating custom target wordlists.1,278
rhinosecuritylabs/sleuthqlA Python script to identify and extract potential SQL injection points from Burp Proxy History files.466
twelvesec/bearerauthtokenTools to facilitate security testing of applications with authorization tokens46
ricardojba/poi-slingerAutomatically identifies serialization issues in PHP applications by forcing them to perform DNS lookups with serialized objects42
yandex/burp-molly-packSecurity checks pack for Burp Suite that extends its functionality with plugins containing active and passive security checks.138