AutoRepeater Burp Plugin https://github.com/nccgroup/AutoRepeater/compare/master...moloch--:AutoRepeater:master https://github.com/nccgroup/AutoRepeater/compare/master...PortSwigger:auto-repeater:master Authmattrix https://www.whiteoaksecurity.com/blog/authorization-testing-authmatrix-part-1/ https://github.com/Excloudx6/AuthMatrix#basic-usage Authmattix https://youtu.be/4IJ_85tG43I?t=1865 https://github.com/SecurityInnovation/AuthMatrix/blob/master/images/img4.png https://github.com/SecurityInnovation/AuthMatrix/compare/master...Charles94jp:AuthMatrix:master https://zuxsecurity.blogspot.com/2018/01/authmatrix-08.html https://github.com/SecurityInnovation/AuthMatrix/compare/master...PortSwigger:auth-matrix:master Burp Molly Pack https://github.com/yandex/burp-molly-pack/commit/dada164c556f0e7b283917bf9c553700a66f4528 Burp molly scanner https://github.com/yandex/burp-molly-scanner#burp-molly-scanner burp script hackve Burp molly scanner' https://github.com/yandex/burp-molly-scanner#burp-molly-scanner rtor to bypass proxy ip restricstions Burp Hotkeys ekyboard shortcuts recommendations GOOD https://twitter.com/ptswarm/status/1544686537794797576/photo/1 Configuring Burp An Adventure in Dealing with Burp Proxy in an Extension https://parsiya.net/blog/2019-04-06-hiding-options-an-adventure-in-dealing-with-burp-proxy-in-an-extension/ https://pentestbook.six2dez.com/others/burp Create Extensions Python Utility to help create your extension https://github.com/parsiya/burputils/ Ruby Example https://github.com/4ARMED/burp_plugins/blob/master/json_beautifier.rb Documentation Proxy Options https://yw9381.github.io/Burp_Suite_Doc_en_us/burp/documentation/desktop/tools/proxy/options/index.html Extensions Admin Panel Finder https://github.com/moeinfatehi/Admin-Panel_Finder Autorize https://medium.com/pentesternepal/access-control-worth-2000-everyone-missed-this-idor-access-control-between-two-admins-9745eaf15d21 https://github.com/Quitten/Autorize https://portswigger.net/bappstore/f9bbac8c4acf4aefa4d7dc92a991af2f Autorize https://youtu.be/5qSq1S2sRC8?t=852 https://trustfoundry.net/the-top-8-burp-suite-extensions-that-i-use-to-hack-web-sites/ BurpJSLinkFinder https://github.com/PortSwigger/js-link-finder Dr Watson https://github.com/prodigysml/Dr.-Watson Inql graphql Burp Extension for burp [here](https://youtu.be/5qSq1S2sRC8?t=753) Sharpener - Burp Extension https://portswigger.net/bappstore/3c5025b0e19d419a8f339ee0c30391dd Extension Lists Awesome Burp Extensions https://github.com/fuzz-security/awesome-burp-extensions Extensions By Hannah https://github.com/Hannah-PortSwigger?tab=repositories Github Burp Extensions Filter https://github.com/topics/burp-extensions Filter out noise in burp Filter out noise in burp tip #10 https://www.infosecmatter.com/bug-bounty-tips-1/ Filter out noise in burp https://twitter.com/sw33tLie/status/1275537548539027457 Howtos Send any traffic through burp. https://github.com/jrmdev/mitm_relay https://trustfoundry.net/the-top-8-burp-suite-extensions-that-i-use-to-hack-web-sites/ Pro tip (Burp) Move extensions to the bottom of the list on the Extender Tab // List of loaded Extensions. Extensions are used in the order they appear on that list and Flow may not log a particular extension if it is above that extension on the list. Resources Fuzz Security / Burp Resources Awesome Burp Extensions by Fuzz Security https://github.com/fuzz-security/awesome-burp-extensions Asesome Burp by Fuzz Security https://github.com/fuzz-security/awesome-burp-suite Scanners https://github.com/PortSwigger/example-scanner-checks https://youtu.be/cqM-MdPkaWo?t=412 <--- Burp Find and Replace rule to do vhost hopping https://github.com/w0ot-net/ParamScraper https://stackoverflow.com/questions/tagged/burp?tab=Votes https://github.com/Static-Flow/BurpSuite-Team-Extension https://github.com/Static-Flow/BurpSuiteAutoCompletion https://twitter.com/_StaticFlow_/status/1367304795342721024 Burp todos https://www.youtube.com/watch?v=sNtxbv7nxJA&t=32s https://github.com/mdsecresearch/BurpSuiteSharpener https://burpbounty.net/burp-bounty-ekoparty-2020/ https://parsiya.net/blog/2019-04-06-hiding-options-an-adventure-in-dealing-with-burp-proxy-in-an-extension/ https://hakin9.org/blind-xss-in-practice-advanced-bug-hunting-with-burp-suite-tutorial-free-course-content/ https://www.youtube.com/watch?v=KoaSRi3tmck https://www.youtube.com/watch?v=35jw4dJtRz0&t=230s #Eko2020 Bounty Hunters | Eduardo Garcia Melia: Burp Bounty - Scan Check Builder https://www.youtube.com/watch?v=t4caslqATi8 https://tryhackme.com/room/burpsuitebasics https://mrxn.net/?tag=burpsuite https://github.com/topics/burp-extensions https://www.youtube.com/watch?time_continue=11&v=35jw4dJtRz0&feature=emb_logo https://https://www.youtube.com/watch?time_continue=11&v=35jw4dJtRz0&feature=emb_logogithub.com/Mr-xn/BurpSuite-collections https://github.com/volkandindar/agartha https://twitter.com/Pethuraj/status/1530773159355379712?cxt=HBwWgMCjsf-Es74qAAAA&cn=ZmxleGlibGVfcmVjcw%3D%3D&refsrc=email https://github.com/BurpsuiteExtensions hqqewwqqttps://github.com/Team-Firebugs/Burp-LFI-tests h211ttps://github.com/1N3/IntruderPayloads 2018 Burp Hacks for Bounty Hunters - James Kettle shares his setup - https://www.youtube.com/watch?v=boHIjDHGmIo BUG BOUNTY :- Burp Suite Bug Bounty Web Hacking learn from Scratch :- Complete Burp Suite Tutorial https://www.youtube.com/watch?v=AH1UcYwxKak https://www.secureideas.com/blog/2015/08/introducing-burp-correlator.html\ https://github.com/redhuntlabs/BurpSuite-Asset_Discover https://github.com/m4ll0k/SecretFinder/tree/master/BurpSuite-SecretFinder https://portswigger.net/web-security/certification https://github.com/rs-loves-bugs/burp-browser-profiles https://www.secureideas.com/blog/2015/05/tip-running-burpsuite-on-mac.html Change Burp Icon https://osxdaily.com/2013/06/04/change-icon-mac/ https://github.com/elkokc/reflector https://github.com/snoopysecurity/awesome-burp-extensions https://portwswigger.net/burp/documentation/desktop/functions/generate-csrf-poc James Kettle burp Setup https://youtu.be/boHIjDHGmIo?t=204 [Wordlists in burp](https://youtu.be/boHIjDHGmIo?t=378) [Grep Extract w intruder](https://youtu.be/boHIjDHGmIo?t=427) [Adding your own active scan check](https://youtu.be/boHIjDHGmIo?t=543) https://import.cdn.thinkific.com/359809/BurpsuiteResourcePDF-201107-173314.pdf https://portswigger.net/burp/pro/video-tutorials?utm_source=burp_suite_professional&utm_medium=embedded_browser&utm_campaign=burp_support https://portswigger.net/blog/burp-suite-professional-feature-roundup https://portswigger.net/news https://youtu.be/rbr7ZmBI9qs?t=278 https://www.hahwul.com/2019/12/29/run-other-application-on-burp-suiteburp/ https://github.com/PortSwigger Burp api Tip https://youtu.be/5qSq1S2sRC8?t=731 [Burp Active Scan by Jason Haddix] He runs an [Active Scan using burp suite](https://youtu.be/uKWu6yhnhbQ?t=4370). He toggles 50 threads, see link for more. https://infosecwriteups.com/leveraging-burp-suite-extension-for-finding-http-request-smuggling-2c0b5321f06d burp etc https://www.youtube.com/playlist?list=PL8j1j35M7wtI4IvNS7ItrM8dTYXx2nYfX echo "Burp Extensions" && echo "Burp Extension Basic Auth Decoder Bypass: https://learn.hacktify.in/courses/take/hacktify-special-chapter-1/downloads/25003636-burpsuite-decode-basic-auth-extension" >> $README curl https://import.cdn.thinkific.com/359809/courses/1386931/firstextension-210608-160308.py -o $HOME/basic-auth-decoder.py Burp Extensions https://github.com/CoreyD97?tab=repositorwies https://github.com/xnl-h4ck3r/burp-extensions/fork https://github.com/xnl-h4ck3r/burp-extensions https://www.kitploit.com/2019/08/iprotate-extension-for-burp-suite-which.html https://github.com/InitRoot/BurpJSLinkFinder https://bugbountyforum.com/tools/proxy-plugins/ Burp https://github.com/arbazkiraak/BurpBLH Burp https://github.com/0xDexter0us/Scavenger https://github.com/danielthatcher/spydom <--- the postmessage alerts that burp is always complaining about, use this to view them. Building an extension resources *---> https://github.com/w0ot-net/ParamScraper/blob/master/ParamScraper.py Burp Cheat Sheet https://www.sans.org/posters/burp-suite-cheat-sheet/ https://www.hackingarticles.in/burp-suite-for-pentester-burps-project-management/ https://github.com/Net-hunter121/API-Wordlist#usage <----- hack apis with burp [Autorize](https://youtu.be/5qSq1S2sRC8?t=852) https://www.kitploit.com/2022/05/graphql-threat-matrix-graphql-threat.html inQL graphql Burp Extension for burp [here](https://youtu.be/5qSq1S2sRC8?t=753) Extender https://www.trenchesofit.com/2022/01/16/burp-suite-custom-parameter-handler/ Browser Extensions Burp Collabertator https://blog.intigriti.com/2021/05/05/bug-bytes-121-free-burp-collaborator-alternative-hacking-chrome-extensions-28k-facebook-oauth-account-takeover/ Burp https://github.com/nccgroup/BurpSuiteHTTPSmuggler https://portswigger.net/burp/documentation/collaborator/deploying https://import.cdn.thinkific.com/359809/BurpsuiteResourcePDF-201107-173314.pdf https://portswigger.net/blog/burp-suite-professional-feature-roundup My Burp Extensions https://portswigger.net/bappstore/aaaa60ef945341e8a450217a54a11646 https://github.com/nccgroup/WCFDSer-ng https://github.com/GoSecure/csp-auditor https://github.com/SmeegeSec/Burp-Importer Flow by Marcin Woloszyn https://www.hackingarticles.in/burp-suite-for-pentester-burps-project-management/ https://kalilinuxtutorials.com/nuclei-burp-plugin/ oast testin g https://portswigger.net/burp/application-security-testing/oast https://www.udemy.com/course/web-application-ethical-hacking/learn/lecture/3305350?start=0#overview https://portswigger.net/blog/a-modern-elastic-design-for-burp-collaborator-server https://portswigger.net/blog/burp-suite-roadmap-for-2022 https://portswigger.net/blog/burp-suite-certification-prices-hacked-for-black-friday https://portswigger.net/blog/the-mystery-of-the-missing-mac-release Burp Documentation https://portswigger.net/burp/documentation/desktop/functions/generate-csrf-poc #### [Burp](https://gist.github.com/ruevaughn/a6da987379f5593d0ab4a878fe1b6baf/575fd3933296ea1eb734fe4e69bd99a01c6d425e#file-burp-L2) **https://apps.burpsuite.guide/** **https://securityzines.com/flyers/burp.html** Burp api Tip https://youtu.be/5qSq1S2sRC8?t=731 https://github.com/InitRoot/BurpJSLinkFinder https://github.com/tristanlatr/burpa https://github.com/mdsecresearch/BurpSuiteSharpener TurboIntruder https://github.com/PortSwigger/turbo-intruder/blob/master/resources/examples/timingAttackWithState.py https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack https://github.com/PortSwigger/turbo-intruder https://web.archive.org/web/20210501000000*/https://www.pentagrid.ch/en/blog/password-reset-code-brute-force-vulnerability-in-AWS-Cognito/ https://github.com/PortSwigger/turbo-intruder/blob/master/decorators.md x8-Burp https://github.com/Excloudx6/x8#burp-suite-integrations Create