{"id":18420247,"url":"https://github.com/anof-cyber/alphascan","last_synced_at":"2025-07-06T10:02:44.458Z","repository":{"id":220305468,"uuid":"743398466","full_name":"Anof-cyber/AlphaScan","owner":"Anof-cyber","description":"A BurpSuite extension for vulnerability Scanning","archived":false,"fork":false,"pushed_at":"2024-02-16T06:08:18.000Z","size":121027,"stargazers_count":27,"open_issues_count":0,"forks_count":2,"subscribers_count":2,"default_branch":"main","last_synced_at":"2025-07-06T10:02:38.545Z","etag":null,"topics":["application-security","appsec","bug-bounty","bugbounty","burp-extensions","burpsuite","pentesting","security","security-scanner","vulnerability","vulnerability-scanners"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/Anof-cyber.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-01-15T06:36:15.000Z","updated_at":"2025-04-14T12:30:55.000Z","dependencies_parsed_at":"2024-11-06T04:35:36.534Z","dependency_job_id":null,"html_url":"https://github.com/Anof-cyber/AlphaScan","commit_stats":null,"previous_names":["anof-cyber/alphascan"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/Anof-cyber/AlphaScan","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Anof-cyber%2FAlphaScan","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Anof-cyber%2FAlphaScan/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Anof-cyber%2FAlphaScan/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Anof-cyber%2FAlphaScan/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/Anof-cyber","download_url":"https://codeload.github.com/Anof-cyber/AlphaScan/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/Anof-cyber%2FAlphaScan/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":263882251,"owners_count":23524457,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["application-security","appsec","bug-bounty","bugbounty","burp-extensions","burpsuite","pentesting","security","security-scanner","vulnerability","vulnerability-scanners"],"created_at":"2024-11-06T04:20:43.267Z","updated_at":"2025-07-06T10:02:44.430Z","avatar_url":"https://github.com/Anof-cyber.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"# AlphaScan\nA BurpSuite extension for vulnerability Scanning\n\n[![Java Build](https://github.com/Anof-cyber/AlphaScan/actions/workflows/maven.yml/badge.svg)](https://github.com/Anof-cyber/AlphaScan/actions/workflows/maven.yml)\n\n### 🚧 Under Development 🚧\n\nThis project is currently under active development. Not all features are implemented, and the code may not be stable. While contributions are appreciated, please note that I am not currently accepting external contributions.\n\n\n## Vulnerabilities\n\n\n\n###### Version  1.0\n\n| Vulnerability                   | Details                                                                                                             |\n|--------------------------------|----------------------------------------------------------------------------------------------------------------------|\n| Blind Time Based Injection     | [Payloads](https://github.com/CyberM0nster/SQL-Injection-Payload-List-/blob/master/Generic%20Time%20Based%20SQL%20Injection%20Payloads)                                  |\n| AWS SSRF                       | [Payloads](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Request%20Forgery/README.md#ssrf-url-for-cloud-instances)                        |\n| Reflected XSS                  | [Payloads](https://github.com/Proviesec/xss-payload-list/tree/main)                                                |\n| Error Based SQL injection      | [Payload-src-github](https://github.com/payloadbox/sql-injection-payload-list) ([Payload-src-twitter](https://x.com/Fabrikat0r/status/1731784913572200720?)) ([Payload-src-twitter](https://twitter.com/intigriti/status/1727669826338914506)) |\n| Forced Browsing | Experimental, likely to be false positive|\n| JSON CSRF| Check for Content type text and No Additional headers like bearer|\n| JWT Token Expiry | |\n| CORS| Check CORS if not check for Common Bypass |\n| Verify session cookie or token | Not Part of Active or Passive Scan, Need to be validated before starting a scan through right click menu on any request with a valid session (Not expired) |\n| Error Messages and Banner Grab| Passive Scanner for Error message or Server Banner|\n| Missing CSP Header             |                                                                                                                      |\n| CSP Header with Insecure Directives |                                                                                                                  |\n| CSP Header Missing Required Directives |                                                                                                            |\n| Missing X-Frame Header         |                                                                                                                      |\n| Missing HSTS Header            |                                                                                                                      |\n| Check If Request with Body support XML Content Type Header |   Partial/ Could be False Positive, will be updated later |\n| Session Identifier (HTTP Only Flag) | Only Available if Session Identifier is found |\n| Session Identifier (Secure Flag) | Only Available if Session Identifier is found|\n\n\n\u003cbr\u003e\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanof-cyber%2Falphascan","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fanof-cyber%2Falphascan","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fanof-cyber%2Falphascan/lists"}