Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
http-terminator — AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms request-smuggling exploits. | Kitploit
Tools/GitHubGitHub/portswigger/http-terminator
Web Vulnerability ScannersPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityFuzzingPenetration TestingUtilities & FrameworksPapers & ResearchAI Security
120121 month agoReviewed by Kitploit
GitHub
portswigger/http-terminator

http-terminator

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms request-smuggling exploits.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

http-terminator

An AI-assisted research pipeline for discovering and exploiting HTTP request-smuggling / response-desynchronisation vulnerabilities. Published as a reference companion to the research; parts are runnable (see the matrix below).

The pipeline

root@kitploit:~
URL / RFC  ──▶  seeker  ──▶  flamer  ──▶  validator  ──▶  investigator
              extract       generate      validate         exploit /
              desync        malformed     against a        confirm /
              vectors       test-cases    target (Burp)    report
StageLanguageRole
seeker/PythonExtract desync techniques from docs/RFCs via Claude
flamer/Java/GradleGenerate malformed HTTP test-cases from those techniques
validator/Java/GradleBurp extension that validates generated requests against a target
investigator/PythonReplicate, confirm, cascade and report on findings

Runnability

StageRuns withStatus
seekerPython 3.11+ + ANTHROPIC_API_KEY✅ self-contained
flamerJava 21 + Gradle + ANTHROPIC_API_KEY✅ self-contained
validatorJava 21 + Gradle + Burp Suite (commercial) + bulkScan (see validator/README)⚠️ needs Burp
investigatorClaude Code + external MCP simulator + Burp Organizer + a target⚠️ needs external pieces (see its README)

Each subdir has its own README with setup and commands.

Data

The pipeline's SQLite databases (seeker.db, flamer's production.db / model_outputs.db, investigator's investigations.db) are not included in this repository — they're gitignored and get regenerated by running each stage.

Ethics & authorisation

These tools find and exploit real vulnerabilities. Only run them against systems you own or are explicitly authorised to test. No real target data is included in this repository.

License

AGPL-3.0 — see LICENSE.

Download Tool