Skip to content

About

ParamProbe is a efficient tool for discovering reflected parameters in web applications. It identifies URL parameters reflected in HTTP responses, helping detect vulnerabilities like Reflected XSS or Injection. Designed for simplicity and speed, it's a must-have for penetration testers, bug bounty hunters, and security researchers.

Resources

Stars

3 stars

Watchers

1 watching

Forks

Latest commit

 

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ParamProbe

ParamProbe is a tool designed to discover reflected parameters on websites. This tool is useful for identifying URL parameters that are vulnerable to attacks such as Reflected XSS.

Features

  • 🔍Automatic Crawling: Explores websites and collects all URL parameters.
  • 🔒Reflected Parameter Detection: Tests parameters reflected in HTTP responses.
  • 🌐Crawling Subdomain: Option to explore subdomains.
  • 🛠️ Custom User-Agent: Supports custom or random User-Agent.
  • 🔄 Automatic Updates: Provides support to update the tool to the latest version.

Installation

go install github.com/fkr00t/paramprobe@latest

Usage

paramprobe -h

This will display help for the tool. Here are all the switches it supports.

Option:
    -u, --url           Target URL to scan.
    -c, --crawl         Crawl subdomains.
    -d, --delay         Delay between requests (e.g., 1s).
    --user-agent        Custom User-Agent.
    --random-agent      Use a random User-Agent.
    -up, --update       Update the tool to the latest version.
    -p, --passive       Perform passive scanning using Wayback Machine and Archive.today.
    -h, --help          Show help message.


example:
    paramprobe -u http://testphp.vulnweb.com -d 1s --random-agent
    paramprobe -u http://testphp.vulnweb.com --user-agent 'MyCustomAgent'
    paramprobe --update

About

ParamProbe is a efficient tool for discovering reflected parameters in web applications. It identifies URL parameters reflected in HTTP responses, helping detect vulnerabilities like Reflected XSS or Injection. Designed for simplicity and speed, it's a must-have for penetration testers, bug bounty hunters, and security researchers.

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages