发现未知类型的注入漏洞
This extension complements Burp's active scanner by using a novel approach capable of finding and confirming both known and unknown classes of server-side injection vulnerabilities. Evolved from classic manual techniques, this approach reaps many of the benefits of manual testing including casual WAF evasion, a tiny network footprint, and flexibility in the face of input filtering.
For more information, please refer to the whitepaper at http://blog.portswigger.net/2016/11/backslash-powered-scanning-hunting.html
The code can be found at https://github.com/portswigger/backslash-powered-scanner Contributions and feature requests are welcome.
1.21 20211015
1.10 20210407
1.03 20190814
1.02 20180606
1.01 20180509
1.0 20180214
0.91 20170612
0.9 20170520
0.86 20161004
This extension requires Burp Suite Pro 1.7.10 or later. To install it, simply use the BApps tab in Burp.
If you want to manually build/install it from source, you'll need to add the following JAR to your libraries: https://commons.apache.org/proper/commons-lang/download_lang.cgi
暂无开放 Issues,或尚未同步最近议题。