“OWASP Penetration Testing Kit”的产品徽标图片

OWASP Penetration Testing Kit

https://pentestkit.co.uk/
4.8(

26 个评分

)
扩展程序开发者工具20,000 用户
OWASP Penetration Testing Kit的项目媒体 5(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 6(屏幕截图)
产品视频缩略图
OWASP Penetration Testing Kit的项目媒体 2(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 3(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 4(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 5(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 6(屏幕截图)
产品视频缩略图
OWASP Penetration Testing Kit的项目媒体 2(屏幕截图)
产品视频缩略图
OWASP Penetration Testing Kit的项目媒体 2(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 3(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 4(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 5(屏幕截图)
OWASP Penetration Testing Kit的项目媒体 6(屏幕截图)

概述

OWASP Penetration Testing Kit

The OWASP Penetration Testing Kit (PTK) browser extension is your all-in-one solution for streamlining your daily AppSec tasks. Whether you’re a penetration tester, a Red Team member, or an AppSec practitioner, OWASP PTK enhances your efficiency and provides deep insights into your target application. Key Features: Runtime Scanning (DAST & IAST & SAST & SCA): Perform Dynamic Application Security Testing, Static Analysis, In-Browser IAST and Software Composition Analysis on the fly. Identify SQL injection, command injection, reflected/stored XSS, SQL auth bypass, XPath injections, JWT attacks, and other complex threats. Static Analysis (SAST): PTK automatically parses loaded JavaScript, HTML, and CSS right in your browser—before any code ever runs. It flags unsafe patterns like `eval()`, `innerHTML`/`outerHTML` injection, insecure cryptographic calls, missing input sanitization, and common anti-patterns. In-Browser IAST (Interactive Application Security Testing): PTK’s built-in IAST engine instruments your app at runtime—right in the browser—tracking taint flows and code execution to flag vulnerabilities as they occur. Catch issues like DOM-based XSS, unsafe `eval`/`innerHTML` usage, open-redirects, and more without leaving your dev tools. JWT Inspector: Analyze, craft, and tamper with JSON Web Tokens. Generate keys, test null signatures, brute-force HMAC secrets, and inject malicious `jwk`, `jku`, or `kid` parameters. Insightful Application Info: One-click visibility into tech stacks, WAFs, security headers, crawled links, and authentication flows. Built-in Proxy & Traffic Log: Capture all HTTP(S) traffic, replay requests in R-Builder, and automate XSS, SQLi, and OS command injection. R-Builder for Request Tampering & Smuggling: Craft and manipulate HTTP requests, including complex request-smuggling techniques. Now with cURL import/export. Cookie Management: Add, edit, remove, block, protect, export, and import cookies from a powerful in-browser editor. Decoder/Encoder Utility: Instantly convert between UTF-8, Base64, MD5, URL-encode/decode, and more formats. Swagger.IO Integration: Browse and interact with API endpoints directly from your Swagger documentation. Selenium Integration: Shift left security by running automated Selenium tests with built-in vulnerability checks. Enhance your AppSec practice with PTK—the extension that makes your browser smarter and your testing faster. Install today and start uncovering vulnerabilities in real time!

4.8 星(5 星制)26 个评分

详细了解结果和评价。

详情

  • 版本
    9.6.0
  • 上次更新日期
    2026年2月5日
  • 大小
    11.43MiB
  • 语言
    English (United Kingdom)
  • 开发者
    网站
    邮箱
    denis.podgurskiy@gmail.com
  • 非交易者
    该开发者尚未将自己标识为交易者。欧盟地区消费者须知:消费者权利可能不适用于您与该开发者达成的合约。

隐私权

管理扩展程序并了解它们在组织中的使用情况

“OWASP Penetration Testing Kit”已就收集和使用用户数据披露了以下信息。 如需了解详情,请查看开发者的privacy policy

OWASP Penetration Testing Kit会处理以下数据:

个人身份信息

该开发者已声明,您的数据:

  • 不会因未获批准的用途出售给第三方
  • 不会为实现与产品核心功能无关的目的而使用或转移
  • 不会为确定信用度或放贷目的而使用或转移

支持

若有任何疑问、建议或问题,请在桌面浏览器中打开此页面

Google 应用