PTK is not only a scanner. The manual tools help you inspect browser state, replay requests, test tokens, and build reproducible proof.
The Proxy/traffic log captures browser-generated HTTP traffic. Use it to understand how the app actually communicates.
Look for:
- API routes with user IDs, object IDs, filters, search terms, and sort fields
- state-changing requests
- redirects and callback URLs
- file upload/download routes
- GraphQL or JSON APIs
- role-specific endpoints
- requests that include JWTs, session cookies, CSRF tokens, or custom auth headers
Send interesting requests to R-Builder for targeted testing.
R-Builder lets you edit, replay, clone, export, and scan individual requests.
- Select a request from the traffic log.
- Send it to R-Builder.
- Change one thing at a time: parameter, header, method, body field, cookie, or token.
- Replay the request.
- Compare response status, body, redirects, timing, and side effects.
- Save useful evidence.
- change numeric IDs to another user's ID
- remove or modify authorization headers
- replay state-changing requests
- test parameter pollution
- change content type or method
- remove CSRF tokens
- change JSON types: string to array, object, null, number, or boolean
- inject XSS, SQLi, command, or template payloads where authorized
- test redirect parameters with same-origin and off-origin URLs
Use cURL export when you need:
- a report reproduction command
- a quick retest outside the browser
- a handoff to another tool
- evidence that can be replayed in a controlled environment
Redact cookies, tokens, and personal data before sharing.
Use JWT Inspector to decode, inspect, craft, and test JSON Web Tokens.
JWTs commonly appear in:
Authorization: Bearer ...- cookies
- localStorage
- sessionStorage
- API responses
- WebSocket or event-stream setup requests
Common checks include:
alg: noneacceptance- weak HMAC secrets
- algorithm confusion
- untrusted
jku,jwk, orkid - missing issuer/audience validation
- stale or overly long expiration
- privilege claims accepted from client-controlled tokens
- token accepted from an unexpected carrier, such as cookie vs header
Record:
- token location
- original header and claims
- modified header and claims
- exact request where the token was used
- server response
- why the behavior proves a security weakness
Never publish full live tokens in reports. Redact secrets and signatures when possible.
Review cookies and browser storage because modern apps often split session state across multiple browser surfaces.
SecureHttpOnlySameSite- domain and path scope
- expiration
- session vs persistent behavior
- sensitive values readable by JavaScript
- duplicate session cookies
- weak or unsigned preference/auth cookies
Review:
- localStorage
- sessionStorage
- IndexedDB
- service-worker caches
- tokens stored in JavaScript-readable locations
- role, tenant, or feature flags controlled by storage
Test whether changing storage values affects authorization, feature access, or API calls.
Request smuggling tests can be disruptive. Only run them when explicitly authorized.
Safe workflow:
- Confirm scope and testing window.
- Use non-production if possible.
- Start with low request volume.
- Capture exact raw requests and responses.
- Stop immediately if instability appears.
- Report impact carefully and include infrastructure context.
Collect:
- frontend and backend indicators
- raw request pair
- response timing and desynchronization evidence
- affected host/path
- reproducibility notes
Use Decoder/Encoder for:
- URL encoding/decoding
- Base64
- JSON escaping
- hashing and comparison
- payload normalization
- nested token or parameter inspection
Use Swagger/API helpers when OpenAPI or Swagger definitions are available. Compare documented API routes with routes seen in traffic and routes discovered in JavaScript bundles.