{"repo":"thesp0nge/nightcrawler-mitm","free":true,"listed":false,"github":"https://github.com/thesp0nge/nightcrawler-mitm","clone":"git clone https://github.com/thesp0nge/nightcrawler-mitm.git","description":"A python program that crawls a website and tries to stress it, polluting forms with bogus data","language":"Python","stars":29,"topics":["crawler","web-crawler","web-crawling","stress-test","offensive-security","offensive-scripts"],"license":"MIT","category":"scrapers-browser-automation","readme_excerpt":"nightcrawler-mitm Version: 0.12.0 A mitmproxy addon for background passive analysis, crawling, and basic active scanning, designed as a security researcher's sidekick. WARNING: BETA Stage - Use with caution, especially active scanning features FEATURES - Acts as an HTTP/HTTPS proxy. - Performs passive analysis: - Security Headers (HSTS, CSP, XCTO, XFO, Referrer-Policy, Permissions-Policy, COOP, COEP, CORP, basic weakness checks). - Cookie Attributes (Secure, HttpOnly, SameSite). - JWT Discovery: Finds and decodes JWTs in headers and JSON responses, checking for alg:none and expired claims. - JS Library Identification: Detects common JavaScript libraries and their versions. - WebSocket Authentication: Warns if a WebSocket connection is established without a session cookie. - Basic Info Disclosure checks (Comments, basic keyword context - Note: API/Key/Secret checks temporarily disabled). - Vulnerability Confidence System: - Assigns confidence levels ( LOW , MEDIUM , HIGH ) to all findings. - Implements dynamic verification (e.g., math checks, canary tokens, stability analysis) to minimize false positives. - Filter findings by minimum confidence using nc min confidence . - Smart Targeting: Optionally skip unlikely parameters (e.g., numeric IDs for XSS) to drastically speed up active scans using nc smart targeting . - Crawls the target application to discover new endpoints. - Runs advanced active scans for: - Reflected XSS (with canary token verification). - SQL Injection (error","default_branch":null,"files":null,"tree":[],"storefront":"/r/thesp0nge","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/thesp0nge/nightcrawler-mitm/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}