Kiterunner Logo

Kiterunner

0
Free
Visit Website

For the longest of times, content discovery has been focused on finding files and folders. While this approach is effective for legacy web servers that host static files or respond with 3xx’s upon a partial path, it is no longer effective for modern web applications, specifically APIs. Kiterunner is a tool that is capable of not only performing traditional content discovery at lightning fast speeds, but also bruteforcing routes/endpoints in modern applications. Modern application frameworks such as Flask, Rails, Express, Django and others follow the paradigm of explicitly defining routes which expect certain HTTP methods, headers, parameters and values. When using traditional content discovery tooling, such routes are often missed and cannot easily be discovered. By collating a dataset of Swagger specifications and condensing it into our own schema, Kiterunner can use this dataset to bruteforce API endpoints by sending the correct HTTP method, headers, path, parameters.

FEATURES

ALTERNATIVES

Automatic authorization enforcement detection extension for Burp Suite

A web application firewall and API security platform that combines API discovery, runtime protection, vulnerability testing, and security posture management.

A tool for brute-forcing GET and POST parameters to discover potential vulnerabilities in web applications.

A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

A simple Swagger-ui scanner that detects old versions vulnerable to various XSS attacks

A free online tool to scan for DOM-based XSS vulnerabilities in HTML, JavaScript, and CSS files.

App-Ray offers comprehensive security analysis and compliance solutions for mobile applications.

A security feature to prevent unexpected manipulation of fetched resources.

PINNED