CaidoReflector
is a passive workflow for Caido that will automatically look for paramater reflections in the HTTP response.
Caution
I would recommend avoiding this workflow for now as it might significantly slow down your Caido project, we are working on a better alternative
- Install EvenBetter extension https://github.com/bebiksior/EvenBetter
- Go to Workflows -> Library
- Search for CaidoReflector and click Add
- Done 🎉
- Download https://github.com/bebiksior/CaidoReflector/blob/main/Reflector.json
- In Caido, navigate to the Workflows page
- Click Import and select the downloaded JSON file.
- Done 🎉
- support query parameters without value
- support JSON request body
- allow users to easily disable scanning POST requests
Feel free to contribute! If you'd like to request a feature or report a bug, please create a GitHub Issue.