Burp-Suite-collections
BurpSuite Related Collection Project, plugins mainly from non-BApp Store (App Store)
All localization or use of BurpSuite is based on the premise that you have configured the Java environment!!! Related Tutorial
Latest version (after December 2022) For activation refer to this project solve it yourself, this project does not provide
New version of Burp (after September 2022) Activation refer to scz's method: Address
This project is only for learning and research related to BurpSuite plugins! Cracked versions are no longer provided! The project has been DMCA'd by Burp official on GitHub, and cracked related files have been deleted. If needed, please go to Blog to download the latest burpsuite_pro_v2020.11.3.jar&BurpSuiteLoader.jar download
Make it an APP on Mac and put it in the dock for one-click launch
Use GitHub Action to package the latest Burp plugins
Penetration Testing Interview Questions 2019 Edition
Plugin Directory plugins Introduction:
- BurpMCP-Ultra --- A high-performance MCP extension framework for Burp Suite, an enhanced BurpSuite plugin for integrating multi-model AI, automated analysis, and intelligent assistant operations during penetration testing. Source
- burp_history --- A Burp Suite historical traffic recording and analysis plugin that integrates HTTP traffic monitoring, management, and team sharing collaboration Source
- DouSql --- A SQL injection detection plugin based on secondary development of Xia Sql Source
- burp_variables --- Allows you to define and use variables in Burp tools Source
- SMS_Bomb_Fuzzer --- Burp suite SMS bomb bypass plugin Source
- APIKit --- An integrated BurpSuite vulnerability detection plugin Source
- TsojanScan --- An integrated BurpSuite vulnerability detection plugin Source
- CloudX --- A rule-based encryption/decryption and signature breaking tool Source
- FastjsonScan4Burp --- A Burp passive scan based fastjson vulnerability detection plugin that performs payload testing on JSON parameters or request bodies in data packets. It aims to help security personnel more conveniently discover, detect, and exploit fastjson vulnerabilities. Currently it implements fastjson detection, version detection, dependency detection, out-of-band and in-band exploitation, and simple WAF bypass functionality. Source
- CaptchaDos --- Burpsuite CAPTCHA DOS attack plugin Source
- BucketVulTools --- Burpsuite bucket misconfiguration vulnerability detection plugin Source
- Auto-SSRF --- An SSRF vulnerability automatic detection plugin based on BurpSuite's new MontoyaAPI Source
- AutoRepeater --- Automated mining of SSRF, Redirect, SQLi vulnerabilities, with custom matching parameters Source
- DetSql --- Quickly detect and mark requests that may contain SQL injection, improving test efficiency Source
- SqlScout --- A SQL injection auxiliary detection and parameter mutation plugin for Burp daily workflow, focusing on "quick screening + manual review"; compared to DetSql, it emphasizes complex parameter structure handling and policy controllability Source
- AutorizePro --- An authorization bypass detection Burp plugin, adding AI analysis module && further optimizing detection logic to significantly reduce false positive rates and improve privilege escalation vulnerability detection efficiency Source
- Zack-AI-Scanner --- An automated web vulnerability scanning Burp plugin based on large language models, supporting AI smart scanning, vulnerability verification, and report export Source
- nowafpls --- Insert garbage characters to bypass WAF Source
- gatherBurp --- Fastjson, permission bypass, unauthorized access, SQL injection, multi-level routing, log4j scanning, and generating specified KB-sized random strings + subdomain + proxy pool Source
- BurpFingerPrint --- Integrated Ehole fingerprint library and common OA weak password brute force plugin Source
- BurpAPIFinder --- API and sensitive information comprehensive extraction plugin Source
- Galaxy --- Efficiently view, edit, and scan plaintext packets in scenarios where HTTP request & response are fully encrypted and signed Source
- BurpAppletPentester --- WeChat mini program Wx_SessionKey encryption/decryption plugin Source
- Burpy --- Python-based front-end encryption/decryption solution Source
- interactsh-collaborator --- Burp plugin for Interact.sh reverse chain platform Source
- burpsuite_hack --- Passive proxy scanning plugin that can detect SQL injection and SSRF vulnerabilities Source
- BypassPro --- Burpsuite plugin for automated permission bypass Source | BypassPro modified upgraded version
- BypassFuzzer-Burp --- A Burpsuite plugin for testing authorization bypass vulnerabilities (401/403 bypass) and URL validation bypass Source
- burp-vps-proxy --- A plugin that automatically creates and deletes an upstream SOCKS5 proxy on most cloud services and applies it Source
- CustomCrypto --- Burp custom encryption/decryption plugin Source
- npscrack --- npscrack: Blue team tool, traceability countermeasure, NPS vulnerability exploitation, NPS exp, NPS poc, one-click exploitation BurpSuite plugin Source
- OneScan --- A recursive directory scanning BurpSuite plugin Source
- OutLook --- An OutLook information collection tool that automatically crawls all contact information after logging into an Outlook account Source
- passive-scan-client-plus --- Maintenance branch of passive-scan-client Source