SQLiBar av bLackn3x
SQLiBar – Pentesting & SQLi Toolkit A Developer Tools extension for security testing, real-time SQL injection pattern detection, request manipulation, parameter discovery, and payload encoding.
Metadata for utvidingar
Skjermbilde
Om denne utvidinga
SQLiBar – Pentesting & SQLi Toolkit
A Developer Tools extension for security testing, real-time SQL injection pattern detection, request manipulation, parameter discovery, payload encoding, and multi-language UI support.
Description
SQLiBar is an advanced web penetration testing tool built into Firefox Developer Tools. Designed for security researchers, penetration testers, and web developers, it streamlines parameter analysis, HTTP request building, SQL injection vulnerability testing, and response inspection directly from your browser.
SQL Injection Detection & Pattern Analysis
Automated response analysis against 100+ database-specific error patterns (MySQL, MariaDB, PostgreSQL, MSSQL, Oracle, SQLite, DB2, Sybase, Access, H2, Firebird, and common ORMs such as PDO, SQLAlchemy, Django, Laravel, Hibernate, Entity Framework, Prisma, and more)
Baseline comparison: set response length and timing baselines to catch subtle anomalies (Boolean-based, Union-based, Error-based, and Time-based indicators)
Reflection detection: highlights payload fragments that appear in the response
Diff view: line-based comparison against the stored baseline body
Visual severity indicators (high / medium / low) with code snippet context for identified error signatures
Smart Page Parameter Scanner
Scans the current page DOM to discover form fields, hidden inputs, URL query parameters, link parameters, data-* attributes, and cookies
Instantly push discovered parameters to the URL query, request body, or payload field with a single click
Live Network Capture & Parameter Aggregator
Real-time monitoring and capturing of HTTP / XHR / Fetch requests
Automatic extraction and aggregation of parameters from headers, query strings, URL-encoded bodies, and nested JSON payloads
Inspect raw request/response headers, bodies, and response previews directly
Filter by All / XHR / Documents / POST and search by URL or method
Payload Presets & Request Manipulation
Built-in payload preset manager with dynamic column generator for UNION-based SQLi tests
Interactive JSON body tree examiner for navigating and selecting deeply nested keys
Custom HTTP header injector (X-Forwarded-For, Authorization, custom cookies, Host rewrite, and more)
Method selection (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS), body editor, and optional page navigation
One-click cURL export of the current request
Response Viewer
Syntax highlighting for JSON and HTML response bodies
Search within the response (case-sensitive option, next/previous match)
Copy full response or body only
Multi-Format Encoder / Decoder
Encode and decode on the fly with 15+ formats: URL, Double URL, Base64, Base64 URL-Safe, Hex (spaced / 0x / \x), ASCII/Decimal, SQL CHAR(), Unicode (\u & %u), HTML Entities, JSON, JWT Decode, ROT13, Binary
Themes & Localization
Multiple built-in color schemes (Neon Green, Cyber Cyan, Violet, Amber, Hot Pink, Electric Blue, Matrix Lime, Mono) plus custom accent color picker
Multi-language interface: Deutsch, English, Español, Русский, 中文 (saved preference)
Permissions Justification
devtools: Integrates natively into Firefox DevTools for a seamless workflow
webRequest / cookies / activeTab: Required to capture live network traffic, inspect response headers, inject payload parameters, and manage cookies for security testing
Github:https://github.com/blackn3x/SQLIBar
Disclaimer
SQLiBar is strictly intended for authorized security testing, educational purposes, and vulnerability research on systems you own or have explicit permission to test.
A Developer Tools extension for security testing, real-time SQL injection pattern detection, request manipulation, parameter discovery, payload encoding, and multi-language UI support.
Description
SQLiBar is an advanced web penetration testing tool built into Firefox Developer Tools. Designed for security researchers, penetration testers, and web developers, it streamlines parameter analysis, HTTP request building, SQL injection vulnerability testing, and response inspection directly from your browser.
SQL Injection Detection & Pattern Analysis
Automated response analysis against 100+ database-specific error patterns (MySQL, MariaDB, PostgreSQL, MSSQL, Oracle, SQLite, DB2, Sybase, Access, H2, Firebird, and common ORMs such as PDO, SQLAlchemy, Django, Laravel, Hibernate, Entity Framework, Prisma, and more)
Baseline comparison: set response length and timing baselines to catch subtle anomalies (Boolean-based, Union-based, Error-based, and Time-based indicators)
Reflection detection: highlights payload fragments that appear in the response
Diff view: line-based comparison against the stored baseline body
Visual severity indicators (high / medium / low) with code snippet context for identified error signatures
Smart Page Parameter Scanner
Scans the current page DOM to discover form fields, hidden inputs, URL query parameters, link parameters, data-* attributes, and cookies
Instantly push discovered parameters to the URL query, request body, or payload field with a single click
Live Network Capture & Parameter Aggregator
Real-time monitoring and capturing of HTTP / XHR / Fetch requests
Automatic extraction and aggregation of parameters from headers, query strings, URL-encoded bodies, and nested JSON payloads
Inspect raw request/response headers, bodies, and response previews directly
Filter by All / XHR / Documents / POST and search by URL or method
Payload Presets & Request Manipulation
Built-in payload preset manager with dynamic column generator for UNION-based SQLi tests
Interactive JSON body tree examiner for navigating and selecting deeply nested keys
Custom HTTP header injector (X-Forwarded-For, Authorization, custom cookies, Host rewrite, and more)
Method selection (GET, POST, PUT, PATCH, DELETE, HEAD, OPTIONS), body editor, and optional page navigation
One-click cURL export of the current request
Response Viewer
Syntax highlighting for JSON and HTML response bodies
Search within the response (case-sensitive option, next/previous match)
Copy full response or body only
Multi-Format Encoder / Decoder
Encode and decode on the fly with 15+ formats: URL, Double URL, Base64, Base64 URL-Safe, Hex (spaced / 0x / \x), ASCII/Decimal, SQL CHAR(), Unicode (\u & %u), HTML Entities, JSON, JWT Decode, ROT13, Binary
Themes & Localization
Multiple built-in color schemes (Neon Green, Cyber Cyan, Violet, Amber, Hot Pink, Electric Blue, Matrix Lime, Mono) plus custom accent color picker
Multi-language interface: Deutsch, English, Español, Русский, 中文 (saved preference)
Permissions Justification
devtools: Integrates natively into Firefox DevTools for a seamless workflow
webRequest / cookies / activeTab: Required to capture live network traffic, inspect response headers, inject payload parameters, and manage cookies for security testing
Github:https://github.com/blackn3x/SQLIBar
Disclaimer
SQLiBar is strictly intended for authorized security testing, educational purposes, and vulnerability research on systems you own or have explicit permission to test.
Vurdert 0 av 0 meldarar
Løyve og data
Påkravde løyve:
- Utvid utviklarverktøya for å få tilgang til dine data i opne faner
- Få tilgang til nettlesarfaner
- Tilgang tiil dataa dine frå alle nettsider
Valfrie løyve:
- Tilgang tiil dataa dine frå alle nettsider
Datainnsamling:
- Utviklaren seier at denne utvidinga ikkje krev datainnsamling.
Meir informasjon
- Lenker for tillegg
- Versjon
- 1.0.1
- Storleik
- 77,84 KB
- Sist oppdatert
- 2 timar sidan (12. aug. 2026)
- Liknande kategoriar
- Lisens
- MIT-lisens
- Versjonshistorikk
- Legg til i samling