Burp Suite

Burp Suite
软件描述
Burp Suite 是一个用于对Web应用程序进行安全测试的集成平台。其各种工具能够无缝协作,支持整个测试流程,从最初对应用程序攻击面的映射与分析,到漏洞的发现与利用……
官方网站
访问软件的官方网站了解更多信息
portswigger.net
什么是 Burp Suite?
Burp Suite 是一个用于对Web应用程序进行安全测试的集成平台。其各种工具能够无缝协作,支持整个测试流程,从对应用程序攻击面的初始测绘与分析,到发现并利用安全漏洞。
🔄 替代方案
27 个选择一个免费的深度网站分析工具,可对安全性、性能、搜索引擎优化(SEO)、无障碍性及其他技术方面进行检测。支持 Windows/macOS/Linux 桌面应用程序版本,以及面向高级用户和 CI/CD 流程的命令行工具版本。此外,还包含离线网页导出功能。

HTTP Toolkit
HTTP Toolkit 是一款美观、跨平台且开源的 HTTP(S) 调试代理、分析器和客户端,内置对现代工具的支持,并可自动拦截来自 Docker、Android 到 iOS 客户端的流量。

mitmproxy
mitmproxy is an SSL-capable man-in-the-middle proxy for HTTP. It provides a console interface that allows traffic flows to be inspected and edited on the fly. It also features mitmdump, a commandline tool that provides a tcpdump-like interface for saving, viewing and...
The Zed Attack Proxy (ZAP) is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.

Fiddler
Web Debugging Proxy that logs all HTTP(S) traffic for comprehensive analysis. It allows manipulation of traffic, supports scripting, and extends with .NET. Debugs virtually any application, implementing man-in-the-middle interception with self-signed certificates. Freeware, ideal for developers.

Charles
Charles is an HTTP proxy / HTTP monitor / Reverse Proxy that enables a developer to view all of the HTTP and SSL / HTTPS traffic between their machine and the Internet. This includes requests, responses and the HTTP headers (which contain the cookies and caching information).

Caido
Caido is a cutting-edge web application security tool that enables users to efficiently identify and assess potential vulnerabilities in their web applications. It can be easily integrated into both personal and enterprise environments, making it adaptable to a wide range of...

Proxyman
Proxyman is a high-performance macOS app, which enables developers to view HTTP/HTTPS requests from apps and domains. Available on macOS, iOS, Windows & Linux.