Skip to content

Releases: naroSEC/Burp-Sensitive-Scanner

Burp Sensitive Scanner v1.1.4

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 14:58

동일한 HTTP 로그를 Sensitive Discoverer 결과와 대조해 확인된 탐지 공백을 보완했습니다.

  • api...key와 secret 주변 문맥에 있는 quoted credential 탐지
  • 127.0.0.0/8 loopback 주소 탐지
  • 실제 .env 파일 참조 범위 개선 및 process.env 오탐 억제
  • 기본 body 한도를 10 MiB로 확대해 큰 JavaScript bundle 누락 감소
  • 대용량 입력의 normalization을 2 MiB로 제한하고 worker queue를 자동 축소해 heap 사용량 제어

숫자 TLD 형태의 가짜 이메일, placeholder, 일반 hash와 낮은 엔트로피 값은 계속 제외합니다.

Burp Sensitive Scanner v1.1.3

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 14:38

Fixes a finding viewer bug where a metadata-only finding could leave the previously selected HTTP message visible, making the table URL and editor content appear unrelated.

Editors are now cleared before every selection. If the scan retention limit omitted raw bytes, the extension restores the exact transaction on demand from Proxy History, Site Map, live capture, or the imported Logger repository using its SHA-256 transaction fingerprint. If the source entry has been removed, the editor stays empty and Finding Details reports that the raw message is unavailable.

Burp Sensitive Scanner v1.1.2

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 14:16

Response findings now focus the matching location when the Response tab is opened. The native Burp editor search highlights the match and moves the caret to its byte offset.

The locator handles raw values plus common URL-encoded, HTML-entity, JSON-escaped, and standalone Base64 representations. Long matches use a bounded search expression to keep the editor responsive.

Burp Sensitive Scanner v1.1.1

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 14:09

The interface is now divided into View and Options. View focuses on scanning, filtering findings, and inspecting HTTP messages; Options contains traffic sources, scan areas, limits, worker count, and rule management.

Scanning now uses a bounded parallel worker queue, skips extraction and decoding for disabled areas, avoids repeated Base64 regex compilation, and removes empty match-list allocations. A 600-response benchmark with approximately 55 KB bodies improved from 11.8 seconds with one worker to 3.1 seconds with four workers while producing identical findings.

Burp Sensitive Scanner v1.1.0

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 13:56

Configurable request and response scan areas, per-rule section controls, custom regular expressions, expanded cloud/token/sensitive-file coverage, a focused finding table, and unmasked matches in the UI and exports.

This release retains the bounded streaming scan introduced in v1.0.1 and groups active rules by scan area to reduce unnecessary matching.

Burp Sensitive Scanner v1.0.1

Choose a tag to compare

@naroSEC naroSEC released this 11 Sep 13:24

Fixes Java heap exhaustion when scanning large Burp projects.

  • Streams Proxy History and Site Map transactions directly into deduplication and detection
  • Skips oversized Montoya messages before copying their request or response bytes
  • Removes repeated defensive byte-array copies from fingerprinting and scan paths
  • Adds byte budgets for live capture, Logger imports, and raw HTTP messages retained by findings
  • Caps findings and throttles Swing progress updates to prevent UI queue growth
  • Shows a concise recovery message if the Burp JVM still runs out of heap

SHA-256: A966CE441FC8A387658C78701785F387BA49C34C9AC74078465F7ECFA1942F58

Burp Sensitive Scanner v1.0.0

Choose a tag to compare

@naroSEC naroSEC released this 10 Sep 14:03

Initial release of Burp Sensitive Scanner.

  • Passive analysis of Proxy History, Site Map, captured Burp traffic, and Logger CSV exports
  • Context-aware secret detection with confidence scoring and false-positive filtering
  • Bounded decoding, transaction/finding deduplication, native HTTP viewers, and masked JSON/CSV export
  • Built for Java 17 and Montoya API 2026.2

SHA-256: 34D2B81F4EC6DC84A04E86B25B6926C66D13014DF890D0527D1DDCD261E662E6