#burp

2026-02-21
Georgeeeeee 🐘 ++cafebug@g0v.social
2026-02-16

年夜飯吃太飽... #burp 🐸

2026-02-02

Me, pretty much every week using Burp Suite for years: It would be great to have a Burp internal task manager to figure out what is burning a full CPU while no requests are going through it.
Meanwhile Burp devs: AI! AI! AI! AI!

#burp #burpsuite

2026-01-18
2026-01-18

It was a burp of such magnitude! The burp that launched a thousand laughs! The burp heard around the world!

#burp #laugh

Who Let The Dogs Out 🐾ashed@mastodon.ml
2026-01-11

Пентест сетевых протоколов и Wi-Fi и защита. 3 полезных совета.

#pentest #scan #waybackMachine #burp

- Обнаружить скрытые эндпоинты и параметры через Wayback Machine + автокраулинг: найти старые версии страниц, API-эндпоинты, бэкапы и забытые параметры.

```sh
waybackurls target.example.com | grep "?" | sort -u | tee params.txt
gf xss params.txt | anew potential_xss.txt # httpx + nuclei для проверки
```

- Автопроверка IDOR/BOLA с заменой параметров в Burp Suite: перехват запросов, смена ID/токенов на значения из других аккаунтов и проверка доступа.

- Burp: Send to Intruder → Positions на ID/user_id → Payloads: список ID из reconnaissance → Attack (Sniper) → Сортировка по Length/Status - поиск различий.

- Поиск уязвимостей в JS-файлах + извлечение секретов: парсинг JavaScript на эндпоинты, секреты (API-ключи, токены) и потенциальные XSS/SSTI.

```sh
cat app.js | jsluice urls | sort -u
cat app.js | secretfinder -reg "AKIA[0-9A-Z]{16}" # LinkFinder + grep
```

Le Néandertal se sent las, lasHydrePrever@mathstodon.xyz
2026-01-07
Milos ConstantinTinolle@hachyderm.io
2026-01-05

JS Analyzer : a powerful #Burp Suite extension for JavaScript static analysis. Extracts API endpoints, URLs, secrets, and email addresses from JavaScript files with intelligent noise filtering.
github.com/jenish-sojitra/JSAn

Constantin MilosTinolle
2026-01-05

JS Analyzer : a powerful Suite extension for JavaScript static analysis. Extracts API endpoints, URLs, secrets, and email addresses from JavaScript files with intelligent noise filtering.
github.com/jenish-sojitra/JSAn

Constantin MilosTinolle@infosec.exchange
2026-01-05

JS Analyzer : a powerful #Burp Suite extension for JavaScript static analysis. Extracts API endpoints, URLs, secrets, and email addresses from JavaScript files with intelligent noise filtering.
github.com/jenish-sojitra/JSAn

2025-12-29

Burp....

#burp

2025-12-19

"And just like that, the mood changed, for the man had burped. He had burped his last burp. He had burped it so loud that the entire universe resonated at the sound of it."

#burp

Nicolas Grégoireagarri.fr@bsky.brid.gy
2025-12-13

Looking for a Christmas gift for yourself? #burp #training #2026 There’s 9 seats left for the English-speaking session, and 5 for the French-speaking one

RE: https://bsky.app/profile/did:plc:d7poh4tbrcxpfhouwkemcelp/post/3m6elrqmexc2s

2025-11-18

Хватит страдать в токсичных отношениях с Burp Suite. Пора быть счастливым с Caido

Burp Suite убедил вас, что настоящий инструмент должен быть тяжёлым, капризным и заставлять подстраиваться под себя. Caido доказал обратное: тот же уровень функциональности, но без боли, без ожидания и без лишних гигабайт. Всё просто работает - быстро, стабильно и без нервов. Страдать было необязательно. Пора наконец выдохнуть и работать с удовольствием. Узнать, как жить счастливо без Burp Suite

habr.com/ru/articles/967644/

#Caido #багхантинг #bugbounty #burp #slonser

2025-10-06

My phone burped! :madjoy:

I think it was notifying me that my bf had sent me a message on Signal. As it was starting to play the notification's sound, it realized I had seen all the messages on my desktop instance of Signal, and decided to stop playing. So I heard only the first note of the notification.

#CellPhone #burp #notifications #Signal

2025-09-17

this is your reminder that if you're using Burp for web app testing, you should be using an extension that lets you use variables in your outgoing requests. variables functionality gives you a single place to update credential, token, and identifier values which improves productivity and reduces false positives. there are a few extensions that provide this functionality and I recommend my extension, Burp Variables, which is purpose-built for it: github.com/0xceba/burp_variabl

#burp #burpsuite #burp_suite #pentesting #pentest #bugbounty #bugbountytips #hacking

2025-09-16
2025-09-11
Furry Belly Doctor Vet AnthonyBellyVetAnthony@gulp.cafe
2025-09-02

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst