IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify IDOR vulnerabilities in web applications. 🚀
☆46Feb 24, 2025Updated last year
Alternatives and similar repositories for IDOR-Scanner
Users that are interested in IDOR-Scanner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Ollama AI Analyzer runs directly on your local computer, using Ollama's AI models to analyze your HTTP requests and responses. This means…☆33Mar 1, 2025Updated last year
- burpsuite extension to analyze javascript files using semgrep☆13Feb 3, 2025Updated last year
- dnsprober is a fast and multipurpose DNS reconnaissance tool designed for efficient DNS probing and enumeration. It supports multiple DNS…☆36Jun 23, 2025Updated last year
- ☆13Mar 6, 2025Updated last year
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆58Nov 6, 2025Updated 9 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- All-in Fuzzer. Burp suite extension for auto fuzzing params, headers, body☆36Apr 9, 2026Updated 4 months ago
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆28Feb 20, 2024Updated 2 years ago
- Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets☆147Jan 21, 2025Updated last year
- ☆92Mar 17, 2025Updated last year
- ☆16Apr 17, 2025Updated last year
- Bounty Prompt is an Open-Source Burp Suite extension by Bounty Security that leverages advanced AI via Burp AI and Groq AI. It enables us…☆125Feb 23, 2025Updated last year
- A Burp Suite extension that converts IP addresses to decimal notation, useful for SSRF bypass and WAF evasion testing. Created by Harshad…☆13Dec 9, 2024Updated last year
- ☆52Dec 16, 2024Updated last year
- Grep subdomains from web pages.☆42Feb 10, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆24Mar 22, 2025Updated last year
- WebSocket and SQL Injection Exploit Script☆41Feb 27, 2025Updated last year
- IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applicatio…☆238Sep 25, 2025Updated 10 months ago
- This tools used for Automating finding of subdomain, and checking for alive subdomain, and gathering js files from all the subdomain and …☆23Jun 28, 2024Updated 2 years ago
- Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc…☆98Mar 12, 2025Updated last year
- NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data…☆62Sep 4, 2024Updated last year
- Looks for parameters in urls☆35Oct 14, 2024Updated last year
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆60Feb 22, 2025Updated last year
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆30Jul 21, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆29Jun 13, 2025Updated last year
- ☆11May 29, 2026Updated 2 months ago
- ☆101Apr 4, 2025Updated last year
- A passive way to find backups/ sensitive information.☆94Jul 10, 2025Updated last year
- A quick and dirty (and a little shitty) burp extension that uses cheap deepseek api to send request and response and maybe found somethin…☆35Jan 26, 2025Updated last year
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆31Oct 23, 2025Updated 9 months ago
- AI/LLM local model integration for analysis of reconftw results☆105May 3, 2025Updated last year
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆58Jul 12, 2026Updated 3 weeks ago
- OpenSSH Vulnerabilities Scanner: Bulk Scanning Tool for 21 different OpenSSH CVEs.☆17Apr 29, 2025Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Magento Security Scanner☆13Jan 10, 2022Updated 4 years ago
- CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)☆44Feb 19, 2025Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆66Apr 16, 2026Updated 3 months ago
- CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE☆18Apr 17, 2025Updated last year
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- ☆57Feb 16, 2025Updated last year
- A New Approach to Directory Bruteforce with WaybackLister v1.0☆233Aug 25, 2025Updated 11 months ago