Github param miner. .
- Github param miner. . Use wordlists of common parameters and send them, look for unexpected behavior from the backend. Param names come from a carefully curated built in wordlist, and it also harvests additional words from all in-scope traffic. It combines advanced diffing logic from Backslash Powered Scanner with a binary search technique to guess up to 65,000 param names per request. Sep 2, 2020 · It combines advanced diffing logic from Backslash Powered Scanner with a binary search technique to guess up to 65,000 param names per request. Apr 11, 2025 · This extension identifies hidden, unlinked parameters. PortSwigger/param-miner - Burp extension to identify hidden, unlinked parameters. Sep 4, 2024 · Contribute to PortSwigger/param-miner development by creating an account on GitHub. Feb 26, 2024 · In this article, I will be talking about how you could look for hidden parameters in Burp Suite by using the “ Param Miner ” extension. James Kettle (PortSwigger's Director of Research) explains how to use Param Miner to detect fat GET cache poisoning vulnerabilities within Burp Suite. It's particularly useful for finding web cache poisoning vulnerabilities. It combines advanced diffing logic from Backslash Powered Scanner with a binary search technique to guess up to 65,536 param names per request. Wordlist examples: Explore all the URL from your targets to find old parameters. efv ocob btow ocjkmpm hekdg xbrawm fqw dlbfy ozwp toynen