reddit hackernews mail facebook facebook linkedin
SessionProbe

SessionProbe

Evaluate user privileges in web applications across a list of URLs.

SessionProbe is a multi-threaded pentesting tool designed to assist in evaluating user privileges in web applications. It takes a user's session token and checks for a list of URLs if access is possible, highlighting potential authorization issues. SessionProbe deduplicates URL lists and provides real-time logging and progress tracking.

SessionProbe is intended to be used with Burp Suite's "Copy URLs in this host" functionality in the Target tab.