1. Download the latest release file; e.g., CustomParameterHandler3.0.py 2. Under Extender > Options > Python Environment, point Burp to the location of your copy of Jython's standalone .jar file. a. If you don't already have Jython's standalone .jar file, download it here. 3. Finally, add…
elespike/burp-cph 的主要功能包括:Burp Suite Extensions, Data Extraction and Analysis。
elespike/burp-cph 的开源替代品包括: shuanx/burpapifinder — 攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。. gh0stkey/hae — HaE is a network traffic analysis tool designed to extract, classify, and highlight specific data fragments within… gh0stkey/caa — CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways. 信息洞察,智探千方!. 0x727/bypasspro. akabe1/upnp-bhunter — Burp Suite Extension useful to inspect UPnP security. adriancitu/burp-tabnabbing-extension — This is a Burp Suite Pro extension that is able to find the “Reverse Tabnabbing” attack. For more information about…
HaE is a network traffic analysis tool designed to extract, classify, and highlight specific data fragments within network messages and HTTP traffic. It functions as an HTTP data extractor and traffic content filter, utilizing a network metadata aggregator to centralize highlighted data fragments and annotations for analysis. The tool identifies high-value network packets by mapping classification results to visual color markers and employs a modular classification system to isolate data fragments from binary or text streams. It distinguishes the severity of matched data by piping extracted c
攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。
CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways. 信息洞察,智探千方!