FlashFuzz: A Browser Extension for Quick URL Fuzzing and Secret Scanning
FlashFuzz是一款专为安全工程师设计的轻量级工具,在浏览器内快速进行侦察。它支持模糊测试所有打开标签页中的URL以发现隐藏端点和潜在秘密(如API密钥),并提供自定义词典、并发请求、扫描JavaScript文件等功能,并可导出结果进行进一步分析。 2025-10-14 04:5:55 Author: www.reddit.com(查看原文) 阅读量:76 收藏

Fast, lightweight, and designed for security engineers who want immediate reconnaissance without leaving the browser. Quickly identify hidden endpoints and potential secrets across all open tabs.

  • Quickly fuzz URLs in all open tabs to discover hidden endpoints.

  • Use custom wordlists or built-in example lists.

  • Concurrent requests with configurable batch size.

  • Scan JavaScript files loaded in each tab for likely secrets (API keys, tokens, AWS keys, etc.).

  • Export findings for further analysis or reporting.

  • Lightweight UI for quick runs and detailed results with request/response snapshots.

  • Open source and free to use.

FlashFuzz Demo

Github: https://github.com/Ademking/Flashfuzz


文章来源: https://www.reddit.com/r/netsecstudents/comments/1o65lfx/flashfuzz_a_browser_extension_for_quick_url/
如有侵权请联系:admin#unsafe.sh