Skip to content

burpsuite插件:主动和被动进行JS扫描并分析其中的可利用点

Notifications You must be signed in to change notification settings

sqlmaping/Burpsuite-JSScan

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

15 Commits
 
 
 
 
 
 

Repository files navigation

Burpsuite JsScan 插件

burpsuite插件:主动和被动进行JS扫描并分析其中的可利用点

  • 目前实现了主动扫描和被动扫描
  • 主动扫描模块使用了珍藏字典
  • 被动扫描模块将会分析每一个经过burpsuite的请求,如果是js文件就会保存

后续功能

  • 排除各种JS库,只分析自定义JS,有效发现目标
  • 具体可利用点的分析,例如ajax语法等
  • 考虑将扫描到的自定义JS文件自动添加到自带字典中,逐步完善字典

开发者

  • 小迪安全团队(许少,人走茶凉)

Burpsuite Jsscan Plugin

Burpsuite plug-in: active and passive JS scanning and analysis of available points

  • At present, active scanning and passive scanning are realized
  • The active scanning module uses a collection dictionary
  • The passive scan module will analyze every request passing through burpsuite, and if it is JS file, it will be saved

Follow Up Functions

  • Exclude all kinds of JS libraries, only analyze custom JS, effectively discover the target
  • The analysis of specific points can be used, such as Ajax syntax
  • Consider automatically adding the scanned custom JS file to the dictionary to improve the dictionary step by step

Developer

  • XiaoDi Team(Xu,Man Go Tea Cool)

1.png


2.png


About

burpsuite插件:主动和被动进行JS扫描并分析其中的可利用点

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages