Active and passive checks
48 passive checks read the traffic you captured; 55 active checks attack it. Both ship in Community.
The Scanner runs two kinds of check. Passive checks read; active checks attack. Both ship in Community — no paywall on any check.
Passive checks (48)
Passive checks analyse the flows you already captured and add no new traffic, so they run safely anywhere. They cover security headers, sensitive-data and secret disclosure, cookies and CSRF-token weakness, CORS, OAuth flows, mixed content, open redirects, clickjacking, CSP detail, SRI, HSTS, stack traces and version leaks, reflected input, DOM XSS, postMessage, outdated JS libraries, sourcemap disclosure, subdomain-takeover and cloud-storage exposure, TLS weaknesses, and more.
The full list:
- API Rate Limit Fingerprinting
- Cacheable Sensitive Response
- Cleartext Password Submission
- Client-Side Response Patterns
- Cloud Storage Misconfiguration
- Content-Type Mismatch
- CORS Misconfiguration
- Credit Card Number Disclosure
- Cross-Domain Referer Leak
- Cross-Origin Isolation (COOP/COEP/CORP)
- CSP Detailed Analysis
- Dangerous Deserialization Content Types
- Debug Endpoint Exposure
- Directory Listing
- DOM Clobbering
- Email Address Disclosure
- Exposed Config / Backup Files
- frame-ancestors
- HSTS Detailed Analysis
- HTML Form Security Issues
- Information Disclosure
- Input Reflection
- Insecure Cookie Configuration
- Internal Path Disclosure
- JavaScript Sourcemap Disclosure
- Missing Security Headers
- Missing Subresource Integrity
- Mixed Content
- OAuth/OIDC Flow Analysis
- Open Redirect
- Outdated JavaScript Library
- Password Autocomplete
- Permissions-Policy Check
- postMessage Misconfiguration
- Potential DOM-Based XSS
- Private IP Address Disclosure
- Referrer-Policy Check
- Reverse Tabnabbing
- Sensitive Data Exposure
- Sensitive Data in URL
- Sensitive Information in Comments
- Session Token in URL
- Software Version Disclosure
- Stack Trace Disclosure
- Subdomain Takeover (dangling-service fingerprint)
- TLS Certificate & Cipher Issues
- ViewState Analysis
- Weak Anti-CSRF Token
Active checks (55)
Active checks send crafted payloads and read how the target responds. Each check tests multiple sub-techniques — here's exactly what each one fires.
Injection
SQL Injection — error-based (DBMS error signatures for MySQL, PostgreSQL,
MSSQL, Oracle, SQLite), time-based blind (SLEEP, pg_sleep, WAITFOR DELAY),
boolean-based blind (true/false differential), UNION-based extraction, stacked
queries, and OOB DNS exfiltration when a callback domain is configured.
OS Command Injection — Unix (;id, `id`, $(id)) and Windows
(|dir, &dir) command injection with error-based and time-based detection.
NoSQL Injection — MongoDB operator injection ($ne, $gt, $regex,
$where), JavaScript $where eval injection, and string-based NoSQL syntax
injection.
XPath Injection — error-based extraction, boolean blind, and XPath data exfiltration from XML backends.
LDAP Injection — query manipulation for authentication bypass, blind LDAP injection, and OOB confirmation.
XML Injection (non-XXE) — structure modification, element injection, and external entity expansion in XML APIs.
Expression Language Injection — Java EL, OGNL, SpEL, and MVEL injection for RCE and info disclosure.
Server-Side JavaScript Injection — eval(), Function(), and
vm.runInContext() in Node.js/Deno back-ends.
SSI (Server-Side Includes) Injection — #exec and #include directive
injection for RCE on SSI-parsing servers.
CSV / Formula Injection — leading =, +, -, @ in exported
spreadsheets that execute in Excel/Sheets.
Email Header Injection — CRLF injection into CC/BCC/Subject fields for spam relay and phishing; OOB confirmation via callback domain.
CRLF Injection / Response Splitting — header injection through CRLF sequences in parameters and headers (CWE-93).
Header Injection — HTTP header injection via CRLF that allows response splitting and header smuggling.
Cross-site scripting
Cross-Site Scripting (XSS) — reflected XSS across HTML body, attribute, JavaScript, URL, and CSS contexts. Payloads survive common WAF filters and test every insertion point.
Stored / Blind XSS — payload planted in stored input (comments, profile fields), with OOB callback confirmation when the payload fires later in an admin panel. Multi-flow reflection correlation.
Prototype Pollution (client-side) — __proto__, constructor.prototype
injection in JavaScript apps leading to XSS, DoS, or security bypass.
Server-Side Prototype Pollution — __proto__ and constructor.prototype
injection in Node.js/JS back-ends with known gadget chain payloads.
Server-side attacks
SSRF (Server-Side Request Forgery) — internal URL probing, cloud metadata
endpoint access (169.254.169.254), and OOB DNS callback confirmation.
XXE (XML External Entity) — file read, SSRF, and DoS through malicious DTDs; OOB exfiltration via callback domain.
Server-Side Template Injection (SSTI) — template expression injection in Jinja2, Twig, FreeMarker, Velocity, Thymeleaf, Mako, and Smarty; OOB detection for blind RCE.
Client-Side Template Injection (CSTI) — raw template expressions reflected into AngularJS, Vue, Alpine, Handlebars client-side renderers.
Path Traversal — directory traversal for reading files outside the web root, across Unix and Windows paths.
File Upload — extension bypass, content-type mismatch, double extension, null-byte injection, polyglot generation, and zip-slip. OOB beacons for blind execution (PHP/JSP/ASP).
Insecure Deserialization — Java (Apache Commons, Spring), PHP, Python (pickle), .NET, and Ruby deserialization gadgets; OOB confirmation.
HTTP protocol attacks
HTTP Request Smuggling — CL.TE, TE.CL, TE.TE obfuscation, H2.CL downgrade, and H2.Desync attacks. Time-based detection across front-end / back-end parser differentials.
Client-Side Desync — header injection probes that trigger differential behaviour from reverse proxies. Identifies redirect gadgets and request smuggling entry points.
HTTP/2-Specific Attacks — pseudo-header injection, header casing violations, CRLF injection, method confusion, and stream manipulation.
Host Header Injection — Host and X-Forwarded-Host manipulation that poisons password reset links, redirects, and cache keys.
HTTP Method Override — X-HTTP-Method-Override, X-Method-Override, and
_method parameter abuse to bypass method restrictions.
HTTP Method Testing — TRACE/TRACK enabled methods and verb tampering where unauthorised methods are accepted.
HTTP Parameter Pollution — duplicate parameters that front-end and back-end parse differently, enabling bypass of filters and WAFs.
Authentication and sessions
JWT Attacks — alg:none bypass, KID injection, JKU/X5U injection, RS256
→ HS256 algorithm confusion, and weak-secret dictionary cracking.
CSRF — missing tokens, token validation bypass, SameSite cookie misconfiguration, and Referer/Origin header bypass.
JSON CSRF — API state change without token, Content-Type confusion to bypass CORS on JSON endpoints (CWE-352).
OAuth / OIDC Active Testing — redirect_uri manipulation, state parameter issues, PKCE bypass, and token leakage.
Session Fixation — URL-based session setting, cookie persistence through authentication, and session non-regeneration.
SAML Signature Bypass — replays the accepted SAMLResponse with its XML Signature stripped — if the server still accepts it, signature validation is broken (CWE-347).
Keycloak IAM Misconfiguration — login page XSS, default scope abuse (CVE-2023-6134), service account enumeration, open registration, and proxy auth bypass.
Default / Weak Credentials — brute-forces common credential pairs (admin/admin, root/root) on login endpoints (CWE-1392).
Password Reset Poisoning — attacker-controlled Host/X-Forwarded-Host injected into password reset endpoints to hijack reset links (CWE-610).
2FA / MFA Bypass — skipping the verification step, brute-forcing OTP codes, and manipulating session state (CWE-287).
Access control and logic
BOLA / IDOR — ID parameter swapping, predictable object reference detection (UUIDv1, sequential IDs), and horizontal privilege escalation probing.
Mass Assignment / Auto-Binding — injecting privileged fields (role,
is_admin, price) into create/update requests.
Vertical Privilege Escalation — modifying role/permission parameters and accessing admin endpoints with user-level credentials (CWE-269).
Workflow / Business Logic Bypass — multi-step workflow endpoints (checkout, payment, verify, confirm) tested for step-skip and prerequisite bypass (CWE-840).
Race Condition — TOCTOU, double-spend, and rate-limit bypass via concurrent requests with barrier-based timing.
Padding Oracle — CBC mode oracle by flipping bytes in encrypted parameters and observing differential responses (CWE-347).
SQL Column Truncation — long strings with admin prefixes to trigger silent DB truncation for username collision (CWE-209).
Infrastructure and caching
Open Redirect — attacker-controlled URLs injected into redirect parameters,
checked for 3xx Location header and meta refresh redirects. Tests scheme-relative
(//evil.com), userinfo (@evil.com), and domain confusion patterns.
CORS Active Probing — sends manipulated Origin headers and checks if the server reflects attacker-controlled origins with credentials.
Cache Poisoning — unkeyed inputs that inject malicious content into cached responses served to other users.
Cache Deception — appending static file extensions to dynamic URLs
(e.g. /account/settings → /account/settings/../../style.css) so CDN/proxy
layers cache authenticated content.
WebSocket Security — Cross-Site WebSocket Hijacking (CSWSH), message injection, protocol confusion, token replay, and Origin validation bypass.
GraphQL (introspection, injection, DoS) — introspection disclosure, batching attacks, field suggestion leaks, alias-based DoS, and directive/fragment abuse.
GraphQL Authorization Bypass — IDOR through GraphQL, field-level authorization bypass, and nested query authorization bypass.
They send real attack traffic, so keep them in scope and off targets you are not cleared to attack.
Insertion points
An active check needs to know where to put its payload. Hugin extracts insertion points from every captured request automatically — URL path segments, query parameters, headers, cookies, body parameters, JSON fields (including deeply nested ones, addressed by JSON pointer), XML elements and attributes, and the raw body — and tests each one. The URL fragment becomes its own point too: it rarely reaches the server, but client-side code reflects it, so it feeds the DOM-XSS, open-redirect, and hash-router checks.
You can restrict which location classes are tested. Aim the Scanner only at query parameters, or only at the body, when that's where the input lives and you want the probe budget spent there.
Structured bodies
Hugin breaks a structured request body into its real fields before it fuzzes them, so you attack the value and not the wrapper:
Each form field becomes its own body parameter. A file part's filename is a separate insertion point — filename path traversal, plus extension and Content-Type bypass.
A {"query":"..."} envelope is opened up. Every inline argument is fuzzed in
place, and $variables are tested as ordinary JSON fields.
Protobuf, gRPC, CBOR, MessagePack, and raw GraphQL documents can't be split into fields, so the whole body is tested as a single raw-body point.
Encoding chains
When a captured value arrives already encoded — base64, URL-encoding, or a stack of both — Hugin records that encoding chain for the insertion point and re-encodes every payload the same way before sending. A payload aimed at a base64'd JSON field lands decoded on the server instead of breaking the encoding and getting rejected. You inject the cleartext attack; Hugin makes it survive the wrapper.
Access control
The Scanner's BOLA/IDOR check is one slice of a larger access-control toolkit. The full broken-access-control families — BOLA, BFLA, IDOR, privilege escalation, and the request-shape tricks around them — run as a dedicated cross-identity audit that replays each request as different identities and diffs the responses. See access-control testing and Authorize.
Active checks can change state: they may submit forms, send mail, or write data. Where that matters, scan a copy, or stick to passive checks plus hand testing in Repeater.
Run passive checks across the whole app for free coverage, then aim active checks at the few endpoints that take input or handle auth. That ratio finds the most per request sent.