This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, ISessionHandlingAction | |
class BurpExtender(IBurpExtender): | |
def registerExtenderCallbacks(self, callbacks): | |
callbacks.registerSessionHandlingAction(CsrfSessionHandler(callbacks.getHelpers())) | |
class CsrfSessionHandler(ISessionHandlingAction): | |
def __init__(self, helpers): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender | |
import jarray | |
req = b"""GET /test?input=foo HTTP/1.1 | |
Host: localhost | |
Upgrade-Insecure-Requests: 1 | |
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 | |
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8 | |
Accept-Language: en-GB,en-US;q=0.8,en;q=0.6 | |
Connection: close |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IScannerCheck, IScanIssue | |
class BurpExtender(IBurpExtender): | |
def registerExtenderCallbacks(self, callbacks): | |
callbacks.registerScannerCheck(ScanCheck(callbacks)) | |
class ScanCheck(IScannerCheck): | |
def __init__(self, callbacks): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IScannerCheck, IScanIssue | |
from java.net import URL | |
import jarray | |
class CustomCheck(IScannerCheck): | |
def __init__(self, callbacks): | |
self.callbacks = callbacks | |
self.helpers = callbacks.getHelpers() |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IHttpListener | |
class BurpExtender(IBurpExtender, IHttpListener): | |
def registerExtenderCallbacks(self, callbacks): | |
self.callbacks = callbacks | |
callbacks.registerHttpListener(self) | |
def processHttpMessage(self, toolFlag, messageIsRequest, message): | |
helpers = self.callbacks.getHelpers() |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IContextMenuFactory, IContextMenuInvocation, IHttpRequestResponse | |
from javax.swing import JMenuItem, AbstractAction, JOptionPane | |
from java.net import Proxy, InetSocketAddress, URL | |
import threading, traceback, sys | |
from urlparse import urlparse | |
def get_request_info(req): | |
return callbacks.getHelpers().analyzeRequest(req.getHttpService(), req.getRequest()) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IHttpListener | |
import json | |
class BurpExtender(IBurpExtender, IHttpListener): | |
def registerExtenderCallbacks(self, callbacks): | |
self.helpers = callbacks.getHelpers() | |
callbacks.registerHttpListener(self) | |
def processHttpMessage(self, toolFlag, messageIsRequest, message): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender | |
from java.io import File | |
class BurpExtender(IBurpExtender): | |
def registerExtenderCallbacks(self, callbacks): | |
args = callbacks.getCommandLineArguments() | |
if '--report' not in args: | |
return | |
output = File(args[args.index('--report') + 1]) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
from burp import IBurpExtender, IScannerInsertionPoint, IScannerInsertionPointProvider | |
import base64, jarray, re | |
class BurpExtender(IBurpExtender): | |
def registerExtenderCallbacks(self, callbacks): | |
callbacks.registerScannerInsertionPointProvider(BasicAuthInsertionPointProvider(callbacks)) | |
class BasicAuthInsertionPointProvider(IScannerInsertionPointProvider): |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
package burp; | |
import org.json.JSONObject; | |
import org.json.JSONArray; | |
import org.json.JSONTokener; | |
import javax.swing.*; | |
import java.awt.event.ActionListener; | |
import java.awt.event.ActionEvent; | |
import java.io.PrintWriter; |
OlderNewer