Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.
☆29Jun 16, 2026Updated 2 months ago
Alternatives and similar repositories for authz-replay
Users that are interested in authz-replay are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 9 months ago
- My Main App Hacking CheckList☆35Jun 20, 2026Updated 2 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 4 months ago
- rep+ — Burp-style HTTP Repeater for Firefox DevTools with built-in AI to explain requests and suggest attacks☆36Jan 8, 2026Updated 8 months ago
- web app monitoring automation☆15Jan 7, 2025Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Open-source passive reconnaissance and exposure discovery tool that leverages VirusTotal and the Wayback Machine to uncover subdomains, U…☆147Jun 23, 2026Updated 2 months ago
- A powerful command-line tool for Google dorking, enabling users to uncover hidden information and vulnerabilities with advanced search qu…☆41Mar 4, 2026Updated 6 months ago
- A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.☆95Updated this week
- BountyLens MCP server — connect Claude Code to your Hunter Tracker☆64Jun 22, 2026Updated 2 months ago
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆97Aug 24, 2026Updated 2 weeks ago
- Burp Suite MCP Assistant in IDE Extension☆15Dec 31, 2025Updated 8 months ago
- This repository is for the Testing ASP.NET ViewState with YSoNet (YSoSerial.NET) workshop.☆25Dec 17, 2025Updated 8 months ago
- Collection of tools, scripts, one-liners, templates, dorks and more☆12Mar 21, 2026Updated 5 months ago
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆65Jul 23, 2026Updated last month
- AI-Powered Active Directory Attack Platform☆29Jul 3, 2026Updated 2 months ago
- ☆10Oct 30, 2019Updated 6 years ago
- ☆24Aug 12, 2026Updated last month
- ☆79May 5, 2025Updated last year
- A Caido plugin to monitor, intercept, and debug JavaScript sinks based on customizable configurations.☆50Apr 8, 2026Updated 5 months ago
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month
- Active network shares enumeration tool.☆39Jul 17, 2026Updated last month
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated 3 weeks ago
- Advanced test for proxy & waf☆13Feb 10, 2026Updated 7 months ago
- This is a companion software based on the Acunetix Web Vulnerability Scanner 13 scanning engine.☆10Oct 17, 2020Updated 5 years ago
- All-round bug bounty skill for Claude Code parallelized agents for smart contract audits (EVM, Move, Solana, TRON), web/API security, an…☆418Aug 29, 2026Updated 2 weeks ago
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆17Jul 2, 2026Updated 2 months ago
- NmapView – Nmap XML Report Viewer | Turn Nmap XML into a searchable, portable HTML report for analysis, triage, and pentest reporting.☆32Jul 7, 2026Updated 2 months ago
- Slides and videos from talks given at cons☆28Jun 22, 2026Updated 2 months ago
- Burp Suite extension to find hardcoded secrets & hidden endpoints in JavaScript. 150+ detection patterns, active JS fetch, low-noise fals…☆90Updated this week
- Modules designed to be used with the Conquest framework.☆22Sep 3, 2026Updated last week
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆17Dec 31, 2024Updated last year
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆16Jun 11, 2026Updated 3 months ago
- ☆48Aug 12, 2025Updated last year
- Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically.☆125Dec 29, 2025Updated 8 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆63Jul 18, 2026Updated last month
- A practical security workbook for reviewing source code, identifying vulnerabilities, validating findings with test cases, and automating…☆29Sep 4, 2026Updated last week
- A full-stack web application that aggregates all HackerOne bug bounty programs that have source code repositories (GitHub, GitLab, Bitbuc…☆17Mar 16, 2026Updated 5 months ago