HTTP file upload scanner for Burp Proxy
Stars
491
Forks
144
Watchers
491
Open Issues
75
Overall repository health assessment
No package.json found
This might not be a Node.js project
Small fix of a fingerping fingerprint, new SVG SSRF technique implemented
4c1a1fcView on GitHubMultipartInjector now also supports replacing file size in the URL
ba14014View on GitHubAdded some more exotic base64 encoders that truncate ending ==, Active Scan is now off by default for manual GUI scans, fixed size burp collaborator now with valid TLS certificate hostname
30b10e1View on GitHubNow also flag XSS with Content-Disposition: attachment, as users might find ways to circumvent this header
9bc723aView on GitHubBetter use the PoC provided overflow value, haven't done a lot of tests yet with other values
b143da4View on GitHubNew XBadManners imagemagick vulnerability detection, shorter bug report details, fix for sleep based payloads of Imagetragick, refactored image modification scripts, changing back default image size to 200x200 (not too good for OCR attacks, but better for performance in various other cases)
88499dbView on GitHubProtect from Burp passing an object where the request is null, if the extension runs out of memory show a different error message and only change the color of the first 100x100 pixels of an image for performance reasons
f442d03View on GitHubReplace JTextPane with JLabel, so that About Tab is rendered correctly in the new dark theme of Burp
58991b9View on GitHub