What's happening in the Burp-verse - Issue #9 📰

#9・
230

subscribers

9

issues

Subscribe to our newsletter

By subscribing, you agree with Revue’s Terms of Service and Privacy Policy and understand that Burp Suite Guide will receive your email address.

What's happening in the Burp-verse - Issue #9 📰
By Burp Suite Guide • Issue #9 • View online
Hi 👋,
I hope this newsletter finds you with a smile on your face. 😊
In this newsletter issue, we will walk through the latest blog posts, extensions, and a security certification from PortSwigger.
If you got this newsletter for the first time, welcome onboard!!! Signing up for the newsletter was your first step in becoming the up-to-date hero of Burp Suite.
Follow Burp Suite Guide on Twitter or LinkedIn to get instant updates on Burp Suite and more. 
Now let’s continue.

Releases
There hasn’t been a stable release since the last newsletter issue. The early adopter release 2021.7.2 has DOM Invader improvements and embedded browser update.
Blog Posts
Have you ever tested an app in a different language - Spanish, Bahasa, Arabic, etc.?
If yes, you will know the hard part about it. I am not talking about finding bugs but rather translating what the functionality is. 
BurpelFish is a Burp extension that helps translate text using Google Translate. This article by Alex Rodriguez shows how to configure the BurpelFish extension. 
Check out the article.
This article shows how to automate a multi-step login using three methods: using Burp macros, Stepper and Turbo Intruder, and then describing each method’s pros and cons. A very informative blog post.
Check out the article.
Extensions
A simple Burp extension that helps find tabnabbing. It detects links with target=”_blank” and rel="opener" attributes. In case the links are user-controllable, then it’s a valid issue.
Source: https://cptwin.lolnet.co.nz/post/2021-07-24-_blank-burp-plugin/
Source: https://cptwin.lolnet.co.nz/post/2021-07-24-_blank-burp-plugin/
A BurpSuite extension to parse 5GC NF OpenAPI 3.0 files to assess 5G core networks.
Source: https://github.com/PentHertz/5GC_API_parse
Source: https://github.com/PentHertz/5GC_API_parse
Tweets
Reduce noise in your proxy logs!
Muhammad Noman
Burp Suite > Proxy > Options > TLS Pass Through.
Add these:
.*\.google\.com
.*\.gstatic\.com
.*\.mozilla\.com
.*\.googleapis\.com
.*\.pki\.goog
No more noise in your logs! #bugbountytips #Bugbounty #CyberSecurity
DirectoryImporter extension supports ffuf
Tanner Barnes
Thanks to a co-worker DirectoryImporter now supports Fuff! Bapp store update soon! https://t.co/QT6bL2Ij7P
One disadvantage of creating Burp extensions in Jython: the code will be stuck with Python 2.7. Jython doesn’t support Python 3 yet.
Cat
So I guess BurpSuite python plug-ins are stuck on 2.7 for a while. Doesn’t seem to be much development on Jython and can’t tell if the Jython 3 roadmap has been updated since 2015.
Others
A security certification from Portswigger. This certification focuses on detecting and exploiting web-based vulnerabilities (XSS, SQLi, OOB attacks, etc.) using Burp Suite Pro. 
Completing modules in Web Security Academy is mandatory before taking the exam
Does it mean PortSwigger will silently add premium modules to Web Security Academy or start charging for the labs?
PortSwigger says that access to Web Security Academy will remain free. The certification fee covers the exam proctoring and infrastructure costs.
Talking about the certification fee, unlike many popular (and costly) security certifications, it’s $99 only.
SimpleAutoBurp by Adan Álvarez, as the name suggests, is a simple Python script to run Burp Suite scans from CLI. It utilizes Burp REST API and doesn’t allow authenticated Burp scans yet. It’s like the stripped-down version of Seltzer.
Finally
Did you learn something new from this newsletter? 🥺
If yes, please share this newsletter with your friends, hackers & pentesters. Tweet about it, post about it on social media, or even forward this newsletter email to others.
If you liked the newsletter, click the 👍 button below. If you have any specific feedback, shoot an email to [email protected].
Many thanks for considering my request.
Until next time 👋
Did you enjoy this issue?
Burp Suite Guide

Your guide to all things Burp Suite !

In order to unsubscribe, click here.
If you were forwarded this newsletter and you like it, you can subscribe here.
Powered by Revue