API Sniffer - Endpoint Detector 제작자: Bahawal Ali
A powerful toolkit for Bug Bounty Hunters. Includes local IDOR/BOLA hunting, API mapping, and team collaboration.
일부 기능은 결제가 필요할 수 있음일부 기능은 결제가 필요할 수 있음
확장 메타 데이터
스크린샷
정보
API Sniffer - Endpoint Detector is the ultimate all-in-one Swiss Army knife for Bug Bounty Hunters, Penetration Testers, and Security Researchers. Designed to run completely in your browser without the need for heavy external proxies like Burp Suite, this toolkit empowers you to intercept, modify, and analyze web traffic on the fly.
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
리뷰어 0명이 0점으로 평가함
권한 및 데이터
필수 권한:
- 클립보드에 데이터 넣기
- 모든 페이지의 콘텐츠 차단
- 방문 기록 보기
- 파일을 다운로드하고 브라우저의 다운로드 기록을 읽고 수정
- 알림 표시
- 브라우저 프록시 설정 제어
- 브라우저 탭에 접근
- 모든 웹사이트에서 사용자의 데이터에 접근
선택적 권한:
- 모든 웹사이트에서 사용자의 데이터에 접근
데이터 수집:
- 개발자는 이 확장 기능이 데이터 수집을 요구하지 않는다고 밝히고 있습니다.
추가 정보
- 부가 기능 링크
- 버전
- 2.5
- 크기
- 1.93 MB
- 최근 업데이트
- 한 달 전 (2026년 8월 9일)
- 관련 카테고리
- 라이선스
- All Rights Reserved
- 개인정보처리방침
- 이 부가 기능에 대한 개인정보처리방침 읽기
- 버전 목록
- 모음집에 추가