JeppW / smugchunksLinks
A black-box scanner for HTTP request smuggling vulnerabilities caused by chunk parsing discrepancies.
☆29Updated 3 months ago
Alternatives and similar repositories for smugchunks
Users that are interested in smugchunks are comparing it to the libraries listed below
Sorting:
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆103Updated last year
- ☆25Updated 10 months ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.☆119Updated 2 years ago
- Burpsuite plugin for Interact.sh☆230Updated last year
- Utility for creating ZipSlip archives☆80Updated 2 years ago
- This exention enables autocompletion within BurpSuite Repeater/Intruder tabs.☆164Updated 4 years ago
- Burp Suite Extension - Trigger actions and reshape HTTP request/response and WebSocket traffic using configurable rules☆105Updated 2 months ago
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆148Updated last year
- ☆97Updated 4 years ago
- CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.☆158Updated last year
- Parse HPROF files from the Spring Boot Heapdump Actuator☆29Updated last year
- Burp Extension that copies a request and builds a FFUF skeleton☆112Updated 2 years ago
- ☆91Updated last year
- Mapping from bug bounty and vulnerability disclosure programs to respective GitHub organizations☆84Updated last week
- Improve automated and semi-automated active scanning in Burp Pro☆64Updated 8 months ago
- A tool for monitoring bug bounty programs across multiple platforms to track scope changes.☆32Updated last week
- Modified Nuclei Templates Version to FUZZ Host Header☆51Updated 4 years ago
- A simple tool to detect vulnerabilities described here https://portswigger.net/research/browser-powered-desync-attacks.☆36Updated 3 years ago
- Wordlist to bruteforce for LFI☆128Updated 6 years ago
- This is the data that powers the PortSwigger URL validation bypass cheat sheet.☆57Updated 4 months ago
- ☆93Updated last month
- Detects request smuggling via HTTP/2 downgrades.☆94Updated 3 years ago
- Results from analyzing data gathered from 1.6 billion subdomains☆32Updated last year
- BChecks collection for Burp Suite Professional☆102Updated last year
- JSSCM detects expired domains for Stored XSS exploitation during browsing.☆56Updated 10 months ago
- Check AWS S3 instances for read/write/delete access☆121Updated 3 years ago
- ☆90Updated 4 years ago
- Client-Side Prototype Pollution Tools☆86Updated 4 years ago
- ☆64Updated 2 years ago
- nuclei-bb-templates☆50Updated 3 years ago