Recon Cockpit 作者: Ali Essam
On-demand recon cockpit for authorized web security research. Scans the current site: passive discovery, a same-origin crawl, parameter extraction with reflection testing, and evidence-backed checks for exposed configs, secrets, and VCS metadata.
1 个用户1 个用户
扩展元数据
关于此扩展
Recon Cockpit is a browser-overlay reconnaissance tool for authorized web security testing. It does nothing on install and nothing on page load — you open it by clicking the toolbar icon (or Alt+Shift+U), and scanning itself is a separate, explicit "Start Smart Scan" click inside the panel.
A scan runs in phases:
- Passive discovery — collects URLs, endpoints, and script references already present on the page.
- Same-origin crawl — follows links to other pages on the same origin (bounded by a configurable page limit and depth), so parameters and forms spread across a multi-page app are all found, not just the current page.
- Parameter extraction — pulls query/form parameters into a searchable, filterable list, each with a ready-to-copy test URL.
- Reflection testing — on request, sends a unique marker in place of a parameter's value and reports whether it comes back unescaped, HTML-escaped, or URL-encoded in the response.
- Targeted checks — read-only requests to common exposed paths (config files, VCS metadata like .git, credential files, API schemas, backups) on the page's own origin, with automatic false-positive suppression for SPA/catch-all routes that return 200 for everything.
Findings are scored by severity (High/Medium/Low/Info), exportable as JSON or CSV, and copyable as a report. All requests are same-origin only, capped in concurrency, and nothing is sent anywhere outside your browser — no telemetry, no data collection.
Built for penetration testers, bug bounty hunters, and developers auditing their own sites. Use only on systems you own or have explicit permission to test.
A scan runs in phases:
- Passive discovery — collects URLs, endpoints, and script references already present on the page.
- Same-origin crawl — follows links to other pages on the same origin (bounded by a configurable page limit and depth), so parameters and forms spread across a multi-page app are all found, not just the current page.
- Parameter extraction — pulls query/form parameters into a searchable, filterable list, each with a ready-to-copy test URL.
- Reflection testing — on request, sends a unique marker in place of a parameter's value and reports whether it comes back unescaped, HTML-escaped, or URL-encoded in the response.
- Targeted checks — read-only requests to common exposed paths (config files, VCS metadata like .git, credential files, API schemas, backups) on the page's own origin, with automatic false-positive suppression for SPA/catch-all routes that return 200 for everything.
Findings are scored by severity (High/Medium/Low/Info), exportable as JSON or CSV, and copyable as a report. All requests are same-origin only, capped in concurrency, and nothing is sent anywhere outside your browser — no telemetry, no data collection.
Built for penetration testers, bug bounty hunters, and developers auditing their own sites. Use only on systems you own or have explicit permission to test.
评分 0(1 位用户)
权限与数据
更多信息