federicodotta / Burp-Suite-Extender-Montoya-Course
This repository contains all the examples related to a series of tutorials that demonstrate how to use the new Montoya API of Burp Suite to create extensions that will greatly simplify our pentester lives.
☆35Updated this week
Related projects ⓘ
Alternatives and complementary repositories for Burp-Suite-Extender-Montoya-Course
- Gopher Tomcat Deployer☆47Updated 6 years ago
- This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.☆54Updated last year
- ☆64Updated 2 years ago
- Burp extension to filter JSON on the fly with JQ queries in the HTTP message viewer.☆45Updated 3 years ago
- Utility for creating ZipSlip archives☆67Updated last year
- ☆29Updated 7 months ago
- tool that generates bypasses for open redirects☆49Updated 2 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆67Updated 2 years ago
- ☆23Updated last year
- Improve automated and semi-automated active scanning in Burp Pro☆60Updated 2 years ago
- A collection of Burp Suite Lambda Filters ~ Bambdas☆22Updated last month
- BurpSuite extension to convert requests into bcheck scripts☆30Updated last year
- Burp Extension that lets you use Burp Collaborator as a DNS server for exfiltrating data via Sqlmap☆36Updated 3 years ago
- Find sources and sinks in js code that could lead to DOM XSS 🔎💧🚰☆22Updated 8 months ago
- An intentionally-vulnerable application for demonstrating the hazards of SpEL expression composition☆26Updated 6 years ago
- ☆21Updated 3 months ago
- Burp extension to generate multi-step CSRF POC.☆29Updated 5 years ago
- A burp-suite plugin that extract all parameter names from in-scope requests☆29Updated 3 years ago
- NotSoCereal: A Deserialization exploit playground☆50Updated 2 years ago
- ☆92Updated 3 years ago
- Burp Suite plugin to copy regex matches from selected requests and/or responses to the clipboard.☆33Updated 2 years ago
- Messy BurpSuite plugin for SQL Truncation vulnerabilities.☆61Updated 4 years ago
- The tool exfiltrates data from Couchbase database by exploiting N1QL injection vulnerabilities.☆73Updated 4 years ago
- ☆36Updated 4 years ago
- Introduction to CYS4-SensitiveDiscoverer, a Burp extension that discovers sensitive information inside HTTP messages.☆17Updated 3 weeks ago
- ☆54Updated 2 years ago
- Chameleon Wordlists☆14Updated 2 years ago
- A Burp Suite extension which augments your proxy traffic by injecting log4shell payloads into headers☆42Updated 2 years ago
- RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2☆60Updated 3 years ago
- Burp Bounty profiles☆82Updated 2 years ago