hetty
ppmap
hetty | ppmap | |
---|---|---|
3 | 3 | |
5,906 | 446 | |
- | - | |
0.0 | 0.0 | |
about 1 year ago | almost 2 years ago | |
Go | Go | |
MIT License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
hetty
- Hetty - An http toolkit for security research.
-
Mitmproxy 8
FWIW: I'm building something in Go (https://github.com/dstotijn/hetty). But it's pretty early stage and not even near the featureset that mitmproxy or Burp Suite has. Also I wouldn't dare say it's more efficient (yet!). But Go has been great so far to build it.
As mentioned elsewhere: (dev friendly) extensibility/add-ons with Go will be an interesting challenge. Haven't looked into it yet.
-
Gopher Gold #14 - Wed Oct 07 2020
dstotijn/hetty (Go): Hetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community.
ppmap
- How do I get the ppmap to fuzz test vulerable website with custom xss json payload to exploit client side prototype pollution cross site script?
- How do I get the ppmap to fuzz test vulerable website with custom xss json payload to exploit prototype pollution cross site script?
- A simple scanner/exploitation tool written in GO which automatically exploits known and existing gadgets (checks for specific variables in the global context) to perform XSS via Prototype Pollution.
What are some alternatives?
mitmproxy - An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
ppfuzz - A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀
lakeFS - lakeFS - Data version control for your data lake | Git for data
interactsh - An OOB interaction gathering server and client library
go-dork - The fastest dork scanner written in Go.
spark-operator - Kubernetes operator for managing the lifecycle of Apache Spark applications on Kubernetes.
urlhunter - a recon tool that allows searching on URLs that are exposed via shortener services
mitmpcap - export mitmproxy traffic to PCAP file
xss-payload-list - 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
xmppmitm - XMPP Man-in-the-Middle, quick & dirty
dalfox - 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.