API Sniffer - Endpoint Detector 作者: Bahawal Ali
A powerful toolkit for Bug Bounty Hunters. Includes local IDOR/BOLA hunting, API mapping, and team collaboration.
某些功能可能需要付费某些功能可能需要付费
扩展元数据
屏幕截图
关于此扩展
API Sniffer - Endpoint Detector is the ultimate all-in-one Swiss Army knife for Bug Bounty Hunters, Penetration Testers, and Security Researchers. Designed to run completely in your browser without the need for heavy external proxies like Burp Suite, this toolkit empowers you to intercept, modify, and analyze web traffic on the fly.
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
评分 0(1 位用户)
权限与数据
必要权限:
- 输入数据到剪贴板
- 拦截任何页面上的内容
- 读取您的浏览历史
- 下载文件和读取与修改浏览器的下载历史
- 向您显示通知
- 控制浏览器的代理设置
- 获取浏览器标签页
- 访问您在所有网站的数据
可选权限:
- 访问您在所有网站的数据
收集的数据:
- 开发者称此扩展无需收集数据。
更多信息