☆1,187Jan 21, 2026Updated last month
Alternatives and similar repositories for http-request-smuggler
Users that are interested in http-request-smuggler are comparing it to the libraries listed below
Sorting:
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3☆2,062Jan 2, 2024Updated 2 years ago
- ☆1,407Jan 22, 2026Updated last month
- Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.☆1,725Dec 15, 2025Updated 2 months ago
- Use HTTP Smuggling Lab to learn HTTP Smuggling.☆346Nov 20, 2022Updated 3 years ago
- ☆562Mar 27, 2025Updated 11 months ago
- Automatic SSRF fuzzer and exploitation tool☆3,489Sep 4, 2025Updated 5 months ago
- Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the ac…☆1,774Apr 26, 2024Updated last year
- A python script that finds endpoints in JavaScript files☆4,286Apr 13, 2024Updated last year
- HTTP parameter discovery suite.☆6,091Feb 20, 2025Updated last year
- SSRF (Server Side Request Forgery) testing resources☆2,483Oct 12, 2024Updated last year
- This tool generates gopher link for exploiting SSRF and gaining RCE in various servers☆3,302Apr 18, 2023Updated 2 years ago
- There is no pre-auth RCE in Jenkins since May 2017, but this is the one!☆607May 17, 2019Updated 6 years ago
- Apache Solr Injection Research☆579Jan 28, 2020Updated 6 years ago
- A Burp Suite extension to help pentesters to bypass WAFs or test their effectiveness using a number of techniques☆736May 4, 2019Updated 6 years ago
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,120Apr 21, 2024Updated last year
- Issues with WebSocket reverse proxying allowing to smuggle HTTP requests☆390Aug 15, 2024Updated last year
- A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon☆1,293Jan 26, 2024Updated 2 years ago
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆8,765Dec 4, 2025Updated 2 months ago
- Automated HTTP Request Repeating With Burp Suite☆890Dec 15, 2021Updated 4 years ago
- An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability