
BurpFlow ist eines der besten Burp-Suite-Automatisierungstools für Bug-Bounty-Jäger und Penetrationstester und wird häufig verwendet, um Recon-Daten über einen Proxy zu laden und Workflows für Webanwendungs-Sicherheitstests zu optimieren.
BurpFlow ist ein leichtgewichtiges Node.js-CLI-Tool, das HTTP-Anfragen über einen Burp-Suite-Proxy leitet und es Sicherheitstestern ermöglicht, Reconnaissance-URLs schnell in Burp zu laden und zu analysieren.
BurpFlow ist ein schnelles, effizientes und minimalistisches Recon-Automatisierungs-CLI-Tool für Penetrationstester, Bug-Bounty-Jäger und Sicherheitsforscher.
Es vereinfacht den Prozess des Sendens von HTTP-Anfragen über einen Burp-Proxy und ermöglicht es dir:
⚠️ HAFTUNGSAUSSCHLUSS: Dieses Tool ist ausschließlich für autorisierte Sicherheitstests und Bildungszwecke bestimmt. Unautorisierte Nutzung ist illegal.
npm install -g burpflow
git clone https://github.com/Cappricio-Securities/burpflow.git
npm install
node burpflow.js -h
127.0.0.1:8080)burpflow -h
burpflow -p 127.0.0.1:8080 -u https://example.com
Erstelle eine Datei (urls.txt):
https://example.com
https://github.com
Ausführen:
burpflow -p 127.0.0.1:8080 -l urls.txt
burpflow -p 127.0.0.1:8080 -l urls.txt -c 8 -t 12000
██████╗ ██╗ ██╗██████╗ ██████╗ ███████╗██╗ ██████╗ ██╗ ██╗
██╔══██╗██║ ██║██╔══██╗██╔══██╗██╔════╝██║ ██╔═══██╗██║ ██║
██████╔╝██║ ██║██████╔╝██████╔╝█████╗ ██║ ██║ ██║██║ █╗ ██║
██╔══██╗██║ ██║██╔══██╗██╔═══╝ ██╔══╝ ██║ ██║ ██║██║███╗██║
██████╔╝╚██████╔╝██║ ██║██║ ██║ ███████╗╚██████╔╝╚███╔███╔╝
╚═════╝ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝ ╚═════╝ ╚══╝╚══╝
Developed by Team : Cappriciosec.com
🚀 BurpFlow - Recon to Burp Automation Tool
Started
┏━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┓
┃ proxy : 192.168.0.103:8080 ┃
┃ Concurrency: 5 | 10000ms ┃
┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛
[✔] Loaded: https://www.example.com [status 200]
[✔] Loaded: https://www.stage.electronics.example.com [status 200]
[✔] Loaded: http://www.sprt8.example.co.jp [status 403]
BurpFlow complete. Check Burp Suite proxy history.
burpflow/
├── burpflow.js
├── includes/
│ ├── help.js
│ ├── utils.js
│ ├── filereader.js
│ ├── validate.js
│ ├── runner.js
├── README.md
└── package.json
ECONNREFUSED → Proxy läuft nicht oder falscher PortInvalid URL → Muss mit http:// oder https:// beginnen-u oder -l angebenMIT-Lizenz
KarthiTheHacker
| Flag | Beschreibung |
|---|
-p, --proxy | Proxy-Adresse (erforderlich), z. B. 127.0.0.1:8080 |
-u, --url | Einzelne URL |
-l, --list | Datei mit URLs |
-c, --concurrency | Parallele Anfragen (Standard: 5) |
-t, --timeout | Timeout in ms (Standard: 10000) |
-h, --help | Hilfe anzeigen |