Client-Side Attacks

Test NameAPI IDDescriptionDetectable Vulnerabilities
AWS S3 Takeoveramazon_s3_takeoverTests for S3 buckets that no longer exist to prevent data breaches and malware distributionAmazon AWS S3 bucket takeover
Brute Force Loginbrute_force_loginTests for the availability of commonly used credentialsBrute Force Login
Cookie Securitycookie_securityTests if the application uses and implements cookies with secure attributesMissing 'httponly' Flag in CookieMissing 'secure' Flag in CookiePredictable Cookie Value
Cross-Site Scripting (XSS)xssTests if various application DOM parameters are vulnerable to JavaScript injectionsCross-Site Scripting (rXSS)
CSS Injectioncss_injectionTests for weaknesses that could allow hackers to inject malicious Cascading Style Sheets (CSS) code.CSS Injection
Default Login Locationdefault_login_locationTests if login form location in the target application is easy to guess and accessibleDefault Login Location
HTML Injectionhtml_injectionTests if various application parameters are vulnerable to HTML injectionHTML Injection
iFrame Injectioniframe_injectionTests for frame injection attacks evaluate the embedding of deceptive elements on legitimate websites, tricking users into unintended interactions that lead to unauthorized actions, data theft, or malicious activities.iFrame Injection
JavaScript Vulnerabilities Scanningretire_jsTests for known JavaScript component vulnerabilitiesJavaScript Component with Known Vulnerabilities
Open Cloud Storageopen_cloud_storageContains Open Buckets, Azure Blob Storage, and Amazon S3 Bucket Takeover testsOpen Cloud Storage
Prototype Pollutionproto_pollutionTests if it is possible to inject properties into existing JavaScript objectsPrototype Pollution
Secret Tokenssecret_tokensTests for exposure of secret API tokens or keys in the target applicationSecret Tokens Leak
Stored Cross-Site Scripting (Stored XSS)stored_xssTests if various application DOM parameters are vulnerable to JavaScript injectionsStored Cross-site scripting (pXSS)
Unvalidated Redirectunvalidated_redirectTests if various application parameters are vulnerable to the injection of a malicious link that can redirect a user without validationUnvalidated Redirect
Version Control Systemversion_control_systemsTests if it is possible to access Version Control System (VCS) resourcesVersion Control System Exposure