Skip to content

Length extension attacks in Burp Suite

License

Notifications You must be signed in to change notification settings

PortSwigger/length-extension-attacks

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Signatures - Length extension attacks in Burp Suite

Burp Suite extension to perform hash length extension attacks on weak signature mechanisms.

Use cases

Examples

Signatures tabs.

Signatures tab

Extension-generated Intruder payloads will be available after messages and hashes are generated on the Signatures tab. Remember to disable URL-encoding for messages (as below).

Signatures payloads

Attack results.

Attack results

TODO

  • RIPEMD
  • Whirlpool
  • Tab for HMAC generation
  • Fix copy message button when padding has line breaks

About

Length extension attacks in Burp Suite

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 99.7%
  • HTML 0.3%