OWASP Penetration Testing Kit από pentestkit.co.uk
Penetration Testing Kit is an extension for application security practitioners, penetration testers, and red teams.
937 χρήστες937 χρήστες
Μεταδεδομένα επέκτασης
Σχετικά με την επέκταση
OWASP Penetration Testing Kit (PTK) is an open-source browser extension for interactive security testing of web applications.
PTK works from the live browser session where the application actually runs. This gives it access to the authenticated workflow, browser-generated traffic, loaded client-side code, application routes and runtime behaviour being tested.
Use OWASP PTK to:
Capture and inspect HTTP requests and responses generated by real browser workflows.
Run selected DAST checks against captured requests, parameters and request bodies.
Analyse JavaScript and HTML loaded by the browser for insecure patterns and source-to-sink data flows.
Observe security-relevant browser behaviour while the application executes using in-browser IAST.
Identify client-side libraries and known vulnerable versions with SCA.
Replay and modify requests with R-Builder, including cURL import and export.
Inspect, edit and test JSON Web Tokens.
Review cookies, browser storage, security headers, application technologies and discovered routes.
Encode, decode and transform data used during manual security testing.
Why test from the browser?
Authenticated applications and single-page applications often depend on state that is difficult to reproduce outside the browser. PTK tests the workflow you are currently using, including its identity, tokens, navigation, API traffic, DOM state and loaded client-side resources.
PTK provides its own extension interface and does not require browser DevTools. Its normal testing workflows do not require traffic to be routed through a separate desktop interception proxy.
For automation and CI/CD, use PTK Agent together with the separate PTK Auto browser extension. OWASP PTK also integrates with OWASP ZAP for combined browser-side and proxy-based security testing.
OWASP PTK is intended for penetration testers, bug bounty hunters, AppSec engineers, developers, QA engineers and security students.
OWASP PTK is free and open source.
Use PTK only against applications where you have explicit authorisation. Active scanning, request modification and token testing can modify application data, generate additional traffic and trigger security monitoring.
PTK works from the live browser session where the application actually runs. This gives it access to the authenticated workflow, browser-generated traffic, loaded client-side code, application routes and runtime behaviour being tested.
Use OWASP PTK to:
Capture and inspect HTTP requests and responses generated by real browser workflows.
Run selected DAST checks against captured requests, parameters and request bodies.
Analyse JavaScript and HTML loaded by the browser for insecure patterns and source-to-sink data flows.
Observe security-relevant browser behaviour while the application executes using in-browser IAST.
Identify client-side libraries and known vulnerable versions with SCA.
Replay and modify requests with R-Builder, including cURL import and export.
Inspect, edit and test JSON Web Tokens.
Review cookies, browser storage, security headers, application technologies and discovered routes.
Encode, decode and transform data used during manual security testing.
Why test from the browser?
Authenticated applications and single-page applications often depend on state that is difficult to reproduce outside the browser. PTK tests the workflow you are currently using, including its identity, tokens, navigation, API traffic, DOM state and loaded client-side resources.
PTK provides its own extension interface and does not require browser DevTools. Its normal testing workflows do not require traffic to be routed through a separate desktop interception proxy.
For automation and CI/CD, use PTK Agent together with the separate PTK Auto browser extension. OWASP PTK also integrates with OWASP ZAP for combined browser-side and proxy-based security testing.
OWASP PTK is intended for penetration testers, bug bounty hunters, AppSec engineers, developers, QA engineers and security students.
OWASP PTK is free and open source.
Use PTK only against applications where you have explicit authorisation. Active scanning, request modification and token testing can modify application data, generate additional traffic and trigger security monitoring.
Βαθμολογήθηκε με 5 από 2 αξιολογητές
Δικαιώματα και δεδομένα
Απαιτούμενα δικαιώματα:
- Κάνει εμφάνιση ειδοποιήσεων σε εσάς
- Έχει πρόσβαση στις καρτέλες περιήγησης
- Έχει πρόσβαση στη δραστηριότητα του προγράμματος περιήγησης κατά την περιήγηση
- Έχει πρόσβαση στα δεδομένα σας για κάθε ιστότοπο
Περισσότερες πληροφορίες
- Έκδοση
- 9.9.8
- Μέγεθος
- 9,46 MB
- Τελευταία ενημέρωση
- 8 μέρες πριν (28 Ιουλ 2026)
- Σχετικές κατηγορίες
- Πολιτική απορρήτου
- Διαβάστε την πολιτική απορρήτου του προσθέτου
- Ιστορικό εκδόσεων
- Ετικέτες
- Προσθήκη σε συλλογή
Ο προγραμματιστής της επέκτασης σάς ζητά να βοηθήσετε τη συνεχή ανάπτυξή της με μια μικρή συνεισφορά.