Burp Suite のオープンソース代替
Burp Suite を置き換える無料・OSS・DL可能な選択肢
Interactive TLS intercepting HTTP proxy for testing — An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
代替: Burp Suite、Charles Proxy、Fiddler
Web application security scanner — The ZAP by Checkmarx Core project
代替: Burp Suite
Network execution tool for security testing — The Network Execution Tool
代替: Burp Suite
CLI tool to screenshot sites and gather server info — EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
代替: Burp Suite、Nuclei
Automated command injection detection and exploit tool — Automated All-in-One OS Command Injection Exploitation Tool
代替: Burp Suite、Commix、Nuclei
Generate Gopher payloads to exploit SSRF — This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
代替: Burp Suite
AFL fuzzer fork for Windows binaries — A fork of AFL for fuzzing Windows binaries
代替: Burp Suite、IDA Pro
Automated web application security testing tool — The Swiss Army knife for automated Web Application Testing
代替: Burp Suite
Python web vulnerability scanner — Web vulnerability scanner written in Python3
代替: Burp Suite、Acunetix
Comprehensive web asset and vulnerability scanner — python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
代替: Burp Suite、Acunetix、Nessus
Web vulnerability scanner and auto-exploiter — X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter
代替: Burp Suite
Browser crawler built for security vulnerability scanning
代替: Burp Suite
Local HTTP traffic workbench — Scriptable local traffic workbench for inspecting, intercepting, replaying, and rewriting HTTP/HTTPS and WebSocket traffic.