Federico Dotta
2024-11-26

Eighth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: BChecks - A quick way to extend Burp Suite Active and Passive Scanner!

security.humanativaspa.it/exte

2024-11-19

Seventh article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: using the Collaborator in Burp Suite plugins!

security.humanativaspa.it/exte

2024-07-30

Sixth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: adding new checks to Burp Suite Active and Passive Scanner!

security.humanativaspa.it/exte

2024-06-19

Fifth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: adding new functionalities to the context menu!

security.humanativaspa.it/exte

2024-02-08

A quick overview and some tips on how to handle and exploit Java applets and serialized Java objects in the present day using Burp Suite.

security.humanativaspa.it/java

2023-08-30

Fourth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: creating new tabs for processing HTTP requests and responses!

security.humanativaspa.it/exte

2023-07-19

Stay tuned for the next part on topic: creating new tabs for processing HTTP requests and responses

2023-07-19

Third article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out!

Topic: inspecting and tampering WebSocket messages!

security.humanativaspa.it/exte

2023-07-05

Stay tuned for next article on topic "inspecting and tampering WebSocket messages".

2023-07-05

The first two articles of the series "Extending Burp Suite for fun and profit - The Montoya way" are out!

The topics of these first two parts are:

- Setting the environment + Hello World
- Inspecting and tampering HTTP requests

security.humanativaspa.it/exte

security.humanativaspa.it/exte

2023-06-29
2023-06-28

Thank you @gellge !

2023-06-28

Next week, I will publish the first two articles in a series on a topic I've been wanting to create material for a long time: creating extensions for Burp Suite. The articles will be structured like lessons in a course and will teach how to use the new Montoya API!

Each article will include a step-by-step explanation, the backend code for a scenario (usually in Flask), and of course, example extension code. At the moment, I don't know the exact number of articles in the series, but I can tell you that first 5 articles are ready!

First articles:
1. Setting the environment + Hello World
2. Inspecting and tampering HTTP requests
3. Inspecting and tampering WebSocket messages
4. Adding HTTP request/response editor tabs
5. Adding actions to the context menu
6. Adding custom checks to the Scanner

Stay tuned!

2022-12-22

Part 4 of the "A journey into IoT" series is out! Topic: internal communications. I tried to write these articles with many details, in order to make them as clear as possible also to security researchers approaching hardware for the first times
security.humanativaspa.it/a-jo

2022-11-22

A fork of protobuf-decoder plugin for Burp Suite with many bug fixes and improvements, useful to test complex applications that make use of Protobuf data format:
security.humanativaspa.it/burp

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst