docs

Active and passive checks

48 passive checks read the traffic you captured; 55 active checks attack it. Both ship in Community.

The Scanner runs two kinds of check. Passive checks read; active checks attack. Both ship in Community — no paywall on any check.

Passive checks (48)

Passive checks analyse the flows you already captured and add no new traffic, so they run safely anywhere. They cover security headers, sensitive-data and secret disclosure, cookies and CSRF-token weakness, CORS, OAuth flows, mixed content, open redirects, clickjacking, CSP detail, SRI, HSTS, stack traces and version leaks, reflected input, DOM XSS, postMessage, outdated JS libraries, sourcemap disclosure, subdomain-takeover and cloud-storage exposure, TLS weaknesses, and more.

The full list:

  1. API Rate Limit Fingerprinting
  2. Cacheable Sensitive Response
  3. Cleartext Password Submission
  4. Client-Side Response Patterns
  5. Cloud Storage Misconfiguration
  6. Content-Type Mismatch
  7. CORS Misconfiguration
  8. Credit Card Number Disclosure
  9. Cross-Domain Referer Leak
  10. Cross-Origin Isolation (COOP/COEP/CORP)
  11. CSP Detailed Analysis
  12. Dangerous Deserialization Content Types
  13. Debug Endpoint Exposure
  14. Directory Listing
  15. DOM Clobbering
  16. Email Address Disclosure
  17. Exposed Config / Backup Files
  18. frame-ancestors
  19. HSTS Detailed Analysis
  20. HTML Form Security Issues
  21. Information Disclosure
  22. Input Reflection
  23. Insecure Cookie Configuration
  24. Internal Path Disclosure
  25. JavaScript Sourcemap Disclosure
  26. Missing Security Headers
  27. Missing Subresource Integrity
  28. Mixed Content
  29. OAuth/OIDC Flow Analysis
  30. Open Redirect
  31. Outdated JavaScript Library
  32. Password Autocomplete
  33. Permissions-Policy Check
  34. postMessage Misconfiguration
  35. Potential DOM-Based XSS
  36. Private IP Address Disclosure
  37. Referrer-Policy Check
  38. Reverse Tabnabbing
  39. Sensitive Data Exposure
  40. Sensitive Data in URL
  41. Sensitive Information in Comments
  42. Session Token in URL
  43. Software Version Disclosure
  44. Stack Trace Disclosure
  45. Subdomain Takeover (dangling-service fingerprint)
  46. TLS Certificate & Cipher Issues
  47. ViewState Analysis
  48. Weak Anti-CSRF Token

Active checks (55)

Active checks send crafted payloads and read how the target responds. Each check tests multiple sub-techniques — here's exactly what each one fires.

Injection

SQL Injection — error-based (DBMS error signatures for MySQL, PostgreSQL, MSSQL, Oracle, SQLite), time-based blind (SLEEP, pg_sleep, WAITFOR DELAY), boolean-based blind (true/false differential), UNION-based extraction, stacked queries, and OOB DNS exfiltration when a callback domain is configured.

OS Command Injection — Unix (;id, `id`, $(id)) and Windows (|dir, &dir) command injection with error-based and time-based detection.

NoSQL Injection — MongoDB operator injection ($ne, $gt, $regex, $where), JavaScript $where eval injection, and string-based NoSQL syntax injection.

XPath Injection — error-based extraction, boolean blind, and XPath data exfiltration from XML backends.

LDAP Injection — query manipulation for authentication bypass, blind LDAP injection, and OOB confirmation.

XML Injection (non-XXE) — structure modification, element injection, and external entity expansion in XML APIs.

Expression Language Injection — Java EL, OGNL, SpEL, and MVEL injection for RCE and info disclosure.

Server-Side JavaScript Injection — eval(), Function(), and vm.runInContext() in Node.js/Deno back-ends.

SSI (Server-Side Includes) Injection — #exec and #include directive injection for RCE on SSI-parsing servers.

CSV / Formula Injection — leading =, +, -, @ in exported spreadsheets that execute in Excel/Sheets.

Email Header Injection — CRLF injection into CC/BCC/Subject fields for spam relay and phishing; OOB confirmation via callback domain.

CRLF Injection / Response Splitting — header injection through CRLF sequences in parameters and headers (CWE-93).

Header Injection — HTTP header injection via CRLF that allows response splitting and header smuggling.

Cross-site scripting

Cross-Site Scripting (XSS) — reflected XSS across HTML body, attribute, JavaScript, URL, and CSS contexts. Payloads survive common WAF filters and test every insertion point.

Stored / Blind XSS — payload planted in stored input (comments, profile fields), with OOB callback confirmation when the payload fires later in an admin panel. Multi-flow reflection correlation.

Prototype Pollution (client-side) — __proto__, constructor.prototype injection in JavaScript apps leading to XSS, DoS, or security bypass.

Server-Side Prototype Pollution — __proto__ and constructor.prototype injection in Node.js/JS back-ends with known gadget chain payloads.

Server-side attacks

SSRF (Server-Side Request Forgery) — internal URL probing, cloud metadata endpoint access (169.254.169.254), and OOB DNS callback confirmation.

XXE (XML External Entity) — file read, SSRF, and DoS through malicious DTDs; OOB exfiltration via callback domain.

Server-Side Template Injection (SSTI) — template expression injection in Jinja2, Twig, FreeMarker, Velocity, Thymeleaf, Mako, and Smarty; OOB detection for blind RCE.

Client-Side Template Injection (CSTI) — raw template expressions reflected into AngularJS, Vue, Alpine, Handlebars client-side renderers.

Path Traversal — directory traversal for reading files outside the web root, across Unix and Windows paths.

File Upload — extension bypass, content-type mismatch, double extension, null-byte injection, polyglot generation, and zip-slip. OOB beacons for blind execution (PHP/JSP/ASP).

Insecure Deserialization — Java (Apache Commons, Spring), PHP, Python (pickle), .NET, and Ruby deserialization gadgets; OOB confirmation.

HTTP protocol attacks

HTTP Request Smuggling — CL.TE, TE.CL, TE.TE obfuscation, H2.CL downgrade, and H2.Desync attacks. Time-based detection across front-end / back-end parser differentials.

Client-Side Desync — header injection probes that trigger differential behaviour from reverse proxies. Identifies redirect gadgets and request smuggling entry points.

HTTP/2-Specific Attacks — pseudo-header injection, header casing violations, CRLF injection, method confusion, and stream manipulation.

Host Header Injection — Host and X-Forwarded-Host manipulation that poisons password reset links, redirects, and cache keys.

HTTP Method Override — X-HTTP-Method-Override, X-Method-Override, and _method parameter abuse to bypass method restrictions.

HTTP Method Testing — TRACE/TRACK enabled methods and verb tampering where unauthorised methods are accepted.

HTTP Parameter Pollution — duplicate parameters that front-end and back-end parse differently, enabling bypass of filters and WAFs.

Authentication and sessions

JWT Attacks — alg:none bypass, KID injection, JKU/X5U injection, RS256 → HS256 algorithm confusion, and weak-secret dictionary cracking.

CSRF — missing tokens, token validation bypass, SameSite cookie misconfiguration, and Referer/Origin header bypass.

JSON CSRF — API state change without token, Content-Type confusion to bypass CORS on JSON endpoints (CWE-352).

OAuth / OIDC Active Testing — redirect_uri manipulation, state parameter issues, PKCE bypass, and token leakage.

Session Fixation — URL-based session setting, cookie persistence through authentication, and session non-regeneration.

SAML Signature Bypass — replays the accepted SAMLResponse with its XML Signature stripped — if the server still accepts it, signature validation is broken (CWE-347).

Keycloak IAM Misconfiguration — login page XSS, default scope abuse (CVE-2023-6134), service account enumeration, open registration, and proxy auth bypass.

Default / Weak Credentials — brute-forces common credential pairs (admin/admin, root/root) on login endpoints (CWE-1392).

Password Reset Poisoning — attacker-controlled Host/X-Forwarded-Host injected into password reset endpoints to hijack reset links (CWE-610).

2FA / MFA Bypass — skipping the verification step, brute-forcing OTP codes, and manipulating session state (CWE-287).

Access control and logic

BOLA / IDOR — ID parameter swapping, predictable object reference detection (UUIDv1, sequential IDs), and horizontal privilege escalation probing.

Mass Assignment / Auto-Binding — injecting privileged fields (role, is_admin, price) into create/update requests.

Vertical Privilege Escalation — modifying role/permission parameters and accessing admin endpoints with user-level credentials (CWE-269).

Workflow / Business Logic Bypass — multi-step workflow endpoints (checkout, payment, verify, confirm) tested for step-skip and prerequisite bypass (CWE-840).

Race Condition — TOCTOU, double-spend, and rate-limit bypass via concurrent requests with barrier-based timing.

Padding Oracle — CBC mode oracle by flipping bytes in encrypted parameters and observing differential responses (CWE-347).

SQL Column Truncation — long strings with admin prefixes to trigger silent DB truncation for username collision (CWE-209).

Infrastructure and caching

Open Redirect — attacker-controlled URLs injected into redirect parameters, checked for 3xx Location header and meta refresh redirects. Tests scheme-relative (//evil.com), userinfo (@evil.com), and domain confusion patterns.

CORS Active Probing — sends manipulated Origin headers and checks if the server reflects attacker-controlled origins with credentials.

Cache Poisoning — unkeyed inputs that inject malicious content into cached responses served to other users.

Cache Deception — appending static file extensions to dynamic URLs (e.g. /account/settings → /account/settings/../../style.css) so CDN/proxy layers cache authenticated content.

WebSocket Security — Cross-Site WebSocket Hijacking (CSWSH), message injection, protocol confusion, token replay, and Origin validation bypass.

GraphQL (introspection, injection, DoS) — introspection disclosure, batching attacks, field suggestion leaks, alias-based DoS, and directive/fragment abuse.

GraphQL Authorization Bypass — IDOR through GraphQL, field-level authorization bypass, and nested query authorization bypass.

They send real attack traffic, so keep them in scope and off targets you are not cleared to attack.

Insertion points

An active check needs to know where to put its payload. Hugin extracts insertion points from every captured request automatically — URL path segments, query parameters, headers, cookies, body parameters, JSON fields (including deeply nested ones, addressed by JSON pointer), XML elements and attributes, and the raw body — and tests each one. The URL fragment becomes its own point too: it rarely reaches the server, but client-side code reflects it, so it feeds the DOM-XSS, open-redirect, and hash-router checks.

You can restrict which location classes are tested. Aim the Scanner only at query parameters, or only at the body, when that's where the input lives and you want the probe budget spent there.

Structured bodies

Hugin breaks a structured request body into its real fields before it fuzzes them, so you attack the value and not the wrapper:

Multipart forms

Each form field becomes its own body parameter. A file part's filename is a separate insertion point — filename path traversal, plus extension and Content-Type bypass.

GraphQL

A {"query":"..."} envelope is opened up. Every inline argument is fuzzed in place, and $variables are tested as ordinary JSON fields.

Opaque bodies

Protobuf, gRPC, CBOR, MessagePack, and raw GraphQL documents can't be split into fields, so the whole body is tested as a single raw-body point.

Encoding chains

When a captured value arrives already encoded — base64, URL-encoding, or a stack of both — Hugin records that encoding chain for the insertion point and re-encodes every payload the same way before sending. A payload aimed at a base64'd JSON field lands decoded on the server instead of breaking the encoding and getting rejected. You inject the cleartext attack; Hugin makes it survive the wrapper.

Access control

The Scanner's BOLA/IDOR check is one slice of a larger access-control toolkit. The full broken-access-control families — BOLA, BFLA, IDOR, privilege escalation, and the request-shape tricks around them — run as a dedicated cross-identity audit that replays each request as different identities and diffs the responses. See access-control testing and Authorize.

Active checks can change state: they may submit forms, send mail, or write data. Where that matters, scan a copy, or stick to passive checks plus hand testing in Repeater.

Run passive checks across the whole app for free coverage, then aim active checks at the few endpoints that take input or handle auth. That ratio finds the most per request sent.

Last updated 2026-07-10.