Test and hack web apps xss, sql injection, file inclusion, support login and CSRF. Developers, QA, Pen Testers.
ABOUT HACKTAB: -------------- HackTab is a web vulnerability testing application in your browser.
When enabled for a targeted domain It watches all communication between your browser and the site you are testing and it identifies each parameter and data type for each parameter.
This allows HackTab to re-create any communication between your browser and the target domain and test all http parameter inputs to the application.
Hacktab only tracks requests to domains you target and includes watermarks on pages it is tracking.
hacktab currently tests for reflected cross site scripting, Persistent XSS, sql injection, local file includes and cross site request forgery.
It is blazingly fast and can handle most web forms including forms with csrf protection.
KNOWN BUGS: ------------ * please report!
INTRODUCTION VIDEO: ------------------- https://www.youtube.com/watchv=gnHfXWGg4Aw CURRENT TESTS: -------------- Cross Site Request Forgery Reflected XSS MySQL Injection - sleep() MS SQL Injection - wait for()()()() generic sql injection - and 1=2 Local File Inclusion COMMON QUESTIONS: ----------------- Q: Does HackTab monitor all of my web traffic A: No.
HackTab ONLY monitors traffic to domains you target in its configuration and ONLY when enabled Q: Does HackTab scan the site when I target it A: No.
HackTab only sends tests for the parameters you target and only sends the tests that you have selected when you scan that single parameter.
All tests are manually triggered.
Q: Where are the tests run from A: The tests are run directly from your web browser.
Q: What permissions does HackTab require A: hacktab requires permission to send http requests to targeted domains and also read the responses from those targeted domains.
Q: Does HackTab store any information about vulnerabilities A: No.
All site data is stored in your local chrome extension.
hacktab uses google analytics to store usage data.
This includes number of tests run and which features users are using.
No site information or identifying information is used or stored anywhere outside of your web browser.
Change Log: ---------- 2.1.1: added support for Persistent XSS !
fixed a bug when counting vulnerabilities on parameters fixed a bug displaying different urls with same parameter names improved error handling and logging various other bug fixes 2.1.0: added testing for csrf vulnerability added flag for server state added success and failure strings bug fix when testing sing
Test SEO/speed/security of 100s of pages in a click! Check broken links, HTML/JavaScript/CSS, URL redirects, duplicate titles...
The all in one Red team extension for web pentester
The simplest and most advanced testing automation tool, using Adaptive Learning and Computer Vision image validation.
Protection from adult content (parental control) and from dangerous sites.
Free Cloud Website and API Load Testing extension for creating and running free website and API load tests.
The Leading Source of Cyber Security, Hacking News, Network Security, DDoS Attacks with In-Depth Coverage of Website Vulnerabilities
Record Selenium and HTTP traffic to create a load and functional tests in less than 10 minutes (Apache JMeter Compatible).
This extension was created at Div Hack, Austin.
see the browser through different perspectives
Information on ADT and home security in general.
Test SEO/speed/security of 100s of pages in a click! Check broken links, HTML/JavaScript/CSS, URL redirects,...
The all in one Red team extension for web pentester
The Best Mod and Extension for mope.io!
The simplest and most advanced testing automation tool, using Adaptive Learning and Computer Vision image...
Practise your Typing Online Now.
This extension is used as a hack on the 2048 Game
Protection from adult content (parental control) and from dangerous sites.
Free Cloud Website and API Load Testing extension for creating and running free website and API load...
The Leading Source of Cyber Security, Hacking News, Network Security, DDoS Attacks with In-Depth Coverage...
...
Extension de navigateur permettant d'auditer des pages web en suivant le référentiel RGAA.
Selenium IDE is an integrated development environment for Selenium tests. It is implemented as a Firefox...
Protection from adult content (parental control) and from dangerous sites.
Your protection on the Internet with extension from Kaspersky Lab
Your protection on the Internet with extension from Kaspersky
Best Content-Security-Policy generator to automatically create Strict CSP policies (with SHA support)...
Allows users of our Rapise automated software testing tool to record and play automated tests against...
Automatic Content Security Policy (CSP) Generator. Generate a Content Security Policy header in minutes...
Penetration Testing Kit is an extension for application security practitioners, penetration testers,...
Because good website security shouldn't only be available to mad scientists! Laboratory is a WebExtension...