{"repo":"0xInfection/XSRFProbe","free":true,"listed":false,"github":"https://github.com/0xInfection/XSRFProbe","clone":"git clone https://github.com/0xInfection/XSRFProbe.git","description":"The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.","language":"Python","stars":1302,"topics":["csrf","crawler","csrf-attacks","token-generation","csrf-scanner","crafted-tokens","spider","csrf-tokens","csrf-poc","xsrf"],"license":"GPL-3.0","category":"scrapers-browser-automation","readme_excerpt":"XSRFProbe The Prime Cross Site Request Forgery Audit & Exploitation Toolkit. About XSRFProbe is an advanced Cross Site Request Forgery) (CSRF/XSRF) Audit and Exploitation Toolkit. Equipped with a powerful crawling engine and numerous systematic checks, it is able to detect most cases of CSRF vulnerabilities, their related bypasses and futher generate exploitable proof of concepts with each found vulnerability. For more info on how XSRFProbe works, see XSRFProbe Internals on wiki. XSRFProbe Wiki • Getting Started • General Usage • Advanced Usage • XSRFProbe Internals • Gallery Some Features - [x] Runs a full battery of systematic checks — backed by a response diffing/benchmark engine — before declaring an endpoint vulnerable. - [x] Detects and actively tampers with many Anti-CSRF token implementations: request-method switch, token removal, empty/duplicated values, non-session-bound tokens, double-submit cookies and custom-header tokens. - [x] Probes Referer and Origin validation with real-world bypasses (header removal, regex/subdomain tricks, Origin: null ) as well as method-override and Content-Type bypasses. - [x] Analyses SameSite cookie protections, with optional subdomain enumeration (via crt.sh) for sibling-domain bypass testing. - [x] Works with a powerful crawler featuring deterministic, bounded crawling and scanning (configurable via --max-urls , --max-depth and --crawl-timeout ). - [x] Optional headless Firefox (Selenium) integration for browser-dependent tests and ","default_branch":null,"files":null,"tree":[],"storefront":"/r/0xInfection","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/0xInfection/XSRFProbe/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}