IDOR Scanner is a Burp Suite extension that automates the detection and enumeration of potentially vulnerable numeric fields to identify IDOR vulnerabilities in web applications. 🚀
☆46Feb 24, 2025Updated last year
Alternatives and similar repositories for IDOR-Scanner
Users that are interested in IDOR-Scanner are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Ollama AI Analyzer runs directly on your local computer, using Ollama's AI models to analyze your HTTP requests and responses. This means…☆33Mar 1, 2025Updated last year
- burpsuite extension to analyze javascript files using semgrep☆13Feb 3, 2025Updated last year
- dnsprober is a fast and multipurpose DNS reconnaissance tool designed for efficient DNS probing and enumeration. It supports multiple DNS…☆36Jun 23, 2025Updated last year
- ☆13Mar 6, 2025Updated last year
- Firebase_Checker is Python tool to analyze APK files and web applications for Firebase-related vulnerabilities. This tool identifies secu…☆59Nov 6, 2025Updated 10 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- All-in Fuzzer. Burp suite extension for auto fuzzing params, headers, body☆36Apr 9, 2026Updated 5 months ago
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆28Feb 20, 2024Updated 2 years ago
- Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets☆149Jan 21, 2025Updated last year
- ☆92Mar 17, 2025Updated last year
- ☆16Apr 17, 2025Updated last year
- Bounty Prompt is an Open-Source Burp Suite extension by Bounty Security that leverages advanced AI via Burp AI and Groq AI. It enables us…☆125Feb 23, 2025Updated last year
- A Burp Suite extension that converts IP addresses to decimal notation, useful for SSRF bypass and WAF evasion testing. Created by Harshad…☆13Dec 9, 2024Updated last year
- ☆52Dec 16, 2024Updated last year
- Grep subdomains from web pages.☆42Feb 10, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆24Mar 22, 2025Updated last year
- WebSocket and SQL Injection Exploit Script☆41Feb 27, 2025Updated last year
- IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applicatio…☆236Sep 25, 2025Updated 11 months ago
- Official TruffleHog Burp Suite Extension. Scan Burp Suite traffic for 800+ different types of secrets (API keys, passwords, SSH keys, etc…☆102Mar 12, 2025Updated last year
- This tools used for Automating finding of subdomain, and checking for alive subdomain, and gathering js files from all the subdomain and …☆23Jun 28, 2024Updated 2 years ago
- NetScan CLI is a command-line tool for retrieving and analyzing IP address information. It provides detailed subnet and organization data…☆62Sep 4, 2024Updated 2 years ago
- Looks for parameters in urls☆35Oct 14, 2024Updated last year
- ex-param is an automated tool designed for finding reflected parameters for XSS vulnerabilities. It crawls a target website, extracts GET…☆60Feb 22, 2025Updated last year
- Gouge is a simple Burp extension to extract or gouge all URLs which are seen in JS files as you visit different websites/webpages in Burp…☆30Jul 21, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- This script automates SQL injection testing using SQLMap with AI-powered decision making.☆31Jun 13, 2025Updated last year
- ☆12May 29, 2026Updated 3 months ago
- ☆100Apr 4, 2025Updated last year
- A passive way to find backups/ sensitive information.☆96Jul 10, 2025Updated last year
- A quick and dirty (and a little shitty) burp extension that uses cheap deepseek api to send request and response and maybe found somethin…☆35Jan 26, 2025Updated last year
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆31Oct 23, 2025Updated 10 months ago
- AI/LLM local model integration for analysis of reconftw results☆106May 3, 2025Updated last year
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- OpenSSH Vulnerabilities Scanner: Bulk Scanning Tool for 21 different OpenSSH CVEs.☆18Apr 29, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Magento Security Scanner☆13Jan 10, 2022Updated 4 years ago
- CVE-2025-24016: Wazuh Unsafe Deserialization Remote Code Execution (RCE)☆43Feb 19, 2025Updated last year
- 0xJS is an AI-powered JavaScript Security Tool☆68Apr 16, 2026Updated 5 months ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆23Mar 16, 2026Updated 6 months ago
- Get list of subsidiaries for a selected company☆32Dec 21, 2024Updated last year
- CVE-2025-22457: Python Exploit POC Scanner to Detect Ivanti Connect Secure RCE☆18Apr 17, 2025Updated last year
- A New Approach to Directory Bruteforce with WaybackLister v1.0☆234Aug 25, 2025Updated last year