API Sniffer - Endpoint Detector 作成者: Bahawal Ali
A powerful toolkit for Bug Bounty Hunters. Includes local IDOR/BOLA hunting, API mapping, and team collaboration.
一部の機能は有料の場合があります一部の機能は有料の場合があります
拡張機能メタデータ
スクリーンショット
この拡張機能について
API Sniffer - Endpoint Detector is the ultimate all-in-one Swiss Army knife for Bug Bounty Hunters, Penetration Testers, and Security Researchers. Designed to run completely in your browser without the need for heavy external proxies like Burp Suite, this toolkit empowers you to intercept, modify, and analyze web traffic on the fly.
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
Whether you are hunting for IDOR/BOLA vulnerabilities, analyzing JavaScript for hidden secrets, or testing CORS misconfigurations, API Sniffer has you covered.
🔥 Key Features:
Live Request Interceptor & Repeater: Capture, modify, and drop HTTP/HTTPS requests in real-time. Instantly replay requests to find vulnerabilities.
Automated IDOR & BOLA Hunting: Automatically swap tokens and headers to hunt for authorization bypasses effortlessly.
CORS Misconfiguration Scanner: One-click bulk scanning of all captured endpoints to detect dangerous CORS policies (Access-Control-Allow-Origin).
Passive SAST & JS Analyzer: Automatically scans loaded JavaScript files for sensitive data leaks, API keys, and hidden endpoints.
OOB (Out-of-Band) Sniffer: Generate unique payloads and track out-of-band interactions directly within the dashboard.
GraphQL & HTTP Smuggling Tools: Map GraphQL schemas and test for advanced smuggling vulnerabilities with ease.
Custom Proxy & Token Swapper: Route traffic through custom proxies and apply dynamic Regex-based rules to incoming and outgoing headers.
Team Collaboration: Built-in Mailbox and World Chat to collaborate, share findings, and communicate with other hunters globally.
Live Speed Meter: Keep track of your network's download and upload speeds in real-time with an injected on-screen widget.
Stop relying on bloated desktop software. Turn your browser into a powerful web application security testing toolkit today!
0 人のレビュー担当者が 0 と評価しました
権限とデータ
必要な権限:
- クリップボードへのデータ入力
- 任意のページのコンテンツをブロックする
- 閲覧履歴の読み取り
- ファイルのダウンロードおよびブラウザーのダウンロード履歴の読み取りと変更
- 通知の表示
- ブラウザーのプロキシ設定の管理
- ブラウザーのタブへのアクセス
- すべてのウェブサイトの保存されたデータへのアクセス
任意の許可設定:
- すべてのウェブサイトの保存されたデータへのアクセス
データ収集:
- 開発者によると、この拡張機能はデータ収集を必要としません。
詳しい情報
- バージョン
- 2.5
- サイズ
- 1.93 MB
- 最終更新日
- 7日前 (2026年8月9日)
- 関連カテゴリー
- ライセンス
- All Rights Reserved
- プライバシーポリシー
- このアドオンのプライバシーポリシーを読む
- バージョン履歴
- コレクションへ追加