{"repo":"Mr-xn/BurpSuite-collections","free":true,"listed":false,"github":"https://github.com/Mr-xn/BurpSuite-collections","clone":"git clone https://github.com/Mr-xn/BurpSuite-collections.git","description":"有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using Burpsuite, no crack version file","language":"HTML","stars":3960,"topics":["burpsuite","burpsuite-extender","burpsuite-tools","hacktool","pentesting","pentest-tool","burp-extensions","hackbar","j2eescan","sqlmap"],"license":"MIT","category":"security-tools","readme_excerpt":"Burp-Suite-collections BurpSuite 相关收集项目，插件主要是非BApp Store（商店） 所有的汉化或者使用burpsuite都是在你配置好了Java环境的前提下！！！相关教程 最新版（202212之后） 激活参考这个项目 自己解决，本项目不提供 新版burp（202209之后） 激活参考scz大佬的方法：地址 本项目仅用于burpsuite插件相关学习研究使用！不再提供破解版！项目已经被burp官方提交到GitHub的DMCA了，删除了破解相关文件,如有需要请前往博客 下载最新burpsuite pro v2020.11.3.jar&BurpSuiteLoader.jar download 在 Mac 下制作成 APP 放在 dock 里一键启动 使用 github action 打包最新的 burp 插件 渗透测试面试问题2019版 插件目录 plugins 介绍: - BurpAPISecuritySuite 一个集侦察、分析、模糊测试、资产管理、外部工具联动与 AI 自动化于一体的专业级 API 安全测试扩展。 源处 - AuthMatrix 用于检测HTTP请求里的IDOR越权漏洞插件。 源处 - BurpHistory2Pcap 是将burp suite的HTTP history请求和响应导出成包含完整TCP会话的PCAP数据包插件。 源处 - mcp-server --- 是 PortSwigger 官方发布的扩展，用来让 Burp Suite 能够直接与 AI 客户端（例如 Claude Desktop）进行双向交互。它实现了 Model Context Protocol (MCP)，让 AI 可以像“远程助手”一样控制 Burp 的工具，例如 Repeater、Proxy、Organizer 等。源处 - BurpSuiteSharpenerEx --- 是一个专门用于增强 Burp Suite 使用体验的扩展，它通过大量 UI 与交互改进，让 Repeater、Intruder、Proxy 等核心工具更好用、更高效。 源处 - TokenTwin-Checker --- 一个专为 Burp Suite 开发的自动化授权测试扩展，用来快速发现 BAC（Broken Access Control）、IDOR（Insecure Direct Object Reference）以及水平越权漏洞。 它的核心功能是：让多个不同用户的身份（Cookie / Token）自动互相重放同一个请求，从而检测是否存在越权访问。 源处 - BurpMCP-Ultra --- 一个为 Burp Suite 打造的高性能 MCP 扩展框架，用于在渗透测试中集成多模型 AI、自动化分析与智能辅助操作的BurpSuite增强插件。 源处 - burp history --- 一款集成了 HTTP 流量监控、管理以及团队共享协作的 Burp Suite 历史流量记录与分析插件 源处 - DouSql --- 基于Xia Sql 二次开发的SQL注入检测插件 源处 - burp variables --- 允许你在Burp工具中定义和使用变量 源处 - SMS Bomb Fuzzer --- Burp suite 短信轰炸辅助绕过插件 源处 - APIKit --- 一个集成的BurpSuite漏洞探测插件 源处 - TsojanScan --- 一个集成的BurpSuite漏洞探测插件 源处 - CloudX --- 一个基于规","default_branch":null,"files":null,"tree":[],"storefront":"/r/Mr-xn","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Mr-xn/BurpSuite-collections/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}