「OWASP Penetration Testing Kit」的項目標誌圖片

OWASP Penetration Testing Kit

https://pentestkit.co.uk/
4.8(

26 個評分

)
擴充功能開發人員工具20,000 使用者
OWASP Penetration Testing Kit的項目媒體 5 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 6 (螢幕截圖)
商品影片縮圖
OWASP Penetration Testing Kit的項目媒體 2 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 3 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 4 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 5 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 6 (螢幕截圖)
商品影片縮圖
OWASP Penetration Testing Kit的項目媒體 2 (螢幕截圖)
商品影片縮圖
OWASP Penetration Testing Kit的項目媒體 2 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 3 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 4 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 5 (螢幕截圖)
OWASP Penetration Testing Kit的項目媒體 6 (螢幕截圖)

總覽

OWASP Penetration Testing Kit

The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application. Key Features: Runtime Scanning (DAST & IAST & SAST & SCA): Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats. Static Analysis (SAST): PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like `eval()`, `innerHTML`/`outerHTML` injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns. In-Browser IAST (Interactive Application Security Testing): PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe `eval`/`innerHTML` usage, open-redirects, and more without leaving your dev tools. JWT Inspector: Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious `jwk`, `jku`, or `kid` parameters. Insightful Application Info: One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows. Built-in Proxy & Traffic Log: Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection. R-Builder for Request Tampering & Smuggling: Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export. Cookie Management: Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor. Decoder/Encoder Utility: Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats. Swagger.IO Integration: Browse and interact with API endpoints directly from your Swagger documentation. Selenium Integration: Shift left security by running automated Selenium tests with built-in vulnerability checks. Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!

4.8 分 (滿分 5 分)26 個評分

進一步瞭解結果與評論。

詳細資料

  • 版本
    9.6.0
  • 已更新
    2026年2月5日
  • 大小
    11.43MiB
  • 語言
    English (United Kingdom)
  • 開發人員
    網站
    電子郵件
    denis.podgurskiy@gmail.com
  • 非交易商
    這位開發人員並未表明自己是交易商。歐盟地區的消費者請注意,消費者權利不適用於你和這位開發人員之間簽訂的合約。

隱私權

管理擴充功能,並瞭解貴機構的擴充功能使用情形

「OWASP Penetration Testing Kit」已揭露下列關於收集及使用資料的資訊。 如需更多詳細資訊,請參閱開發人員的《privacy policy》。

OWASP Penetration Testing Kit 會處理下列資料:

個人識別資訊

這位開發者就你的資料做出下列聲明:

  • 經核准的用途外,不會將你的資料販售給第三方
  • 不會基於與商品核心功能無關的目的,使用或轉移資料
  • 不會為了確認信用度或基於貸款目的,使用或轉移資料

支援

如有疑問或建議,請使用電腦版瀏覽器開啟這個頁面

Google 應用程式