Hercules | DAST 作者: Hercules
Powerful web application security scanner. Analyze XSS, SQLi, ports, API, S3, subdomains and more.
3 个用户3 个用户
扩展元数据
屏幕截图
关于此扩展
Hercules DAST (Dynamic Application Security Testing) — a professional tool for web application security analysis directly in your browser.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
🔍 Features:
• robots.txt — sensitive paths analysis (/admin, /api, /.env, /backup)
• sitemap.xml — hidden and sensitive URL discovery
• Scripts — HTTP/HTTPS check, external scripts, outdated libraries
• DOM XSS — vulnerability detection (innerHTML, eval, document.write)
• Forms — CSRF tokens, passwords in GET, autocomplete
• Security Headers — CSP, X-Frame-Options, X-Content-Type-Options
• Cookies — sensitive cookie analysis
• CORS — wildcard origin check
• Ports — open port scanning (80,443,8080,8443,3000,5000,8000)
• API endpoints — Swagger, OpenAPI, GraphQL discovery
• SQL injection — active form testing
• XSS test — active form testing
• Directories — brute force common paths (admin, .env, backup, .git)
• S3 buckets — open AWS S3 bucket discovery
• Subdomains — crt.sh and common subdomain enumeration
📊 Results are displayed with severity statistics (Critical, High, Medium, Low) and can be exported to JSON or HTML.
🛡️ All data is processed locally — nothing is sent to external servers.
Developed for pentesters, developers, and security professionals.
评分 0(1 位用户)
权限与数据
更多信息
- 附加组件链接
- 版本
- 1.0.0
- 大小
- 63.47 KB
- 上次更新
- 2 个月前 (2026年3月27日)
- 相关分类
- 版本历史
- 添加到收藏集