Burp Suite extensins

๐—™๐—ข๐—ฅ ๐—ช๐—˜๐—• ๐—ฃ๐—˜๐—ก๐—˜๐—ง๐—ฅ๐—”๐—ง๐—œ๐—ข๐—ก ๐—ง๐—˜๐—ฆ๐—ง๐—œ๐—ก๐—š

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ” ๐—”๐—จ๐—ง๐—›๐—ข๐—ฅ๐—œ๐—ญ๐—”๐—ง๐—œ๐—ข๐—ก & ๐—”๐—–๐—–๐—˜๐—ฆ๐—ฆ ๐—–๐—ข๐—ก๐—ง๐—ฅ๐—ข๐—Ÿ

โ€ข BurpLay โ†’ replay requests to detect privilege escalation

โ€ข AuthMatrix โ†’ test access across roles

โ€ข Autorize โ†’ auto-detect authorization flaws

โ€ข Auth Analyzer โ†’ test with custom tokens

โ€ข Burp SessionAuth โ†’ session-based privilege issues

โ€ข Authz โ†’ quick authorization testing

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ” ๐—ฅ๐—˜๐—ค๐—จ๐—˜๐—ฆ๐—ง ๐—”๐—จ๐—ง๐—ข๐— ๐—”๐—ง๐—œ๐—ข๐—ก

โ€ข AutoRepeater โ†’ automate request replay + diff

โ€ข IncrementMe Please โ†’ auto-increment parameters

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ” ๐—ฅ๐—˜๐—–๐—ข๐—ก & ๐——๐—œ๐—ฆ๐—–๐—ข๐—ฉ๐—˜๐—ฅ๐—ฌ

โ€ข LinkFinder โ†’ extract endpoints from JS

โ€ข JS Miner / JS Parser โ†’ find sensitive data in JS

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ” ๐—ง๐—ข๐—ž๐—˜๐—ก & ๐—”๐—จ๐—ง๐—› ๐—ง๐—˜๐—ฆ๐—ง๐—œ๐—ก๐—š

โ€ข JWT Editor โ†’ test JWT vulnerabilities

โ€ข Turbo Intruder โ†’ high-speed attacks (race, brute)

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿงช ๐—™๐—จ๐—ญ๐—ญ๐—œ๐—ก๐—š & ๐—ฆ๐—–๐—”๐—ก๐—ก๐—œ๐—ก๐—š

โ€ข ActiveScan++ โ†’ improved scanning coverage

โ€ข Backslash Powered Scanner โ†’ injection detection

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿ“ฆ ๐—”๐——๐—ฉ๐—”๐—ก๐—–๐—˜๐—— ๐—”๐—ง๐—ง๐—”๐—–๐—ž๐—ฆ

โ€ข HTTP Request Smuggler โ†’ find smuggling bugs

โ€ข Content Type Converter โ†’ bypass filters

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐Ÿง  ๐—ฃ๐—ฅ๐—ข๐——๐—จ๐—–๐—ง๐—œ๐—ฉ๐—œ๐—ง๐—ฌ

โ€ข Logger++ โ†’ advanced request logging

โ€ข Flow โ†’ visualize request flow

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

โš ๏ธ ๐—ฅ๐—˜๐—”๐—Ÿ๐—œ๐—ง๐—ฌ

Installing tools โ‰  finding bugs

Understanding logic = finding bugs

โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

๐ŸŽฏ ๐—จ๐—ฆ๐—˜ ๐—ง๐—›๐—œ๐—ฆ ๐—Ÿ๐—œ๐—ž๐—˜ ๐—” ๐—ฃ๐—ฅ๐—ข

Start with recon โ†’ test auth โ†’ fuzz โ†’ automate โ†’ verify