Payloads for the app you are paid to test

An appsec tester who has to argue with the model about whether XSS is allowed on example.com is not testing the app. They are testing the filter.

Appsec engineers and pentesters with a written scope that includes the host they are sending payloads to.

Why the mainstream APIs fail here

The API refuses a polyglot payload, a SSRF URL, or a mass-assignment body because it looks like an attack. It is an attack, on the staging host in the RoE.

How Redline is used for this

Describe the endpoint, the stack, the control you already tried. Ask for the next payload. Hit the in-scope host from your own tooling, not from Redline. Redline is the writer, not the scanner.

A working loop

  1. Stay on in-scope hosts.
  2. Generate payloads, send them from your proxy.
  3. Cap the tester's key so a fuzz loop has a ceiling.

Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.

Related