Marksman
Overview
Highlight dynamic endpoints on webpages
The purpose of this tool is to assist with casual web application penetration testing during large scope engagements where pages may contain dozens or hundreds of links and references to additional endpoints. The tool aims to give testers visual indicators that can help them streamline their attention and focus on elements of interests for further testing without clicking through large numbers of static resources. In 1 click, the tool will highlight in yellow all href elements that refer to pages with the potential for dynamic functionality (asp, php, aspx, jsp, jspx, etc.). The tool will also highlight in red all href elements that contain HTTP GET parameters, after identifying these via regular expression. Finally the tool highlights in magenta any input form elements that result in dynamic HTTP POST requests. This should ideally assist penetration testers in focusing quickly on elements of interest for further investigation. If you want to have the functionality running continuously, simply select the INFINITE MODE checkbox and press the FIRE button. The plugin will automatically perform targeting during navigation until the checkbox is deselected by the user. The tool is equally useful for reconnaissance on search results page to visually identify interesting endpoints containing the aforementioned properties.
0 out of 5No ratings
Google doesn't verify reviews. Learn more about results and reviews.
Details
- Version1.2
- UpdatedOctober 29, 2024
- Offered bypn.allardcoutu
- Size38.84KiB
- LanguagesEnglish (United States)
- Developer
Email
pn.allardcoutu@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes
Support
For help with questions, suggestions, or problems, please open this page on your desktop browser