• Stars
    star
    145
  • Rank 254,144 (Top 6 %)
  • Language
    Java
  • License
    GNU General Publi...
  • Created over 11 years ago
  • Updated over 7 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

GUI Burp Plugin to ease discovering of security holes in web applications

Burp Sentinel

Eases discovery of common security holes in web applications.

With BurpSentinel it is possible for the penetration tester to quickly and easily send a lot of malicious requests to parameters of a HTTP request. Not only that, but it also shows a lot of information of the HTTP responses, corresponding to the attack requests. Its easy to find low-hanging fruits and hidden vulnerabilities like this, and allows the tester to focus on more important stuff!

Features

  • Attack payloads already inside
  • Identification of reflected XSS, and stored XSS
  • Identification of SQL injections (non-blind)
  • Indicators and visual aid for the user to identify blind/fullblind SQL injections
  • Diff original and modified requests easily

Other

What it cannot do:

  • Find DOM Injections
  • Exploit vulnerabilities

Alternatives:

More Repositories

1

avred

Analyse your malware to surgically obfuscate it
Python
367
star
2

lxd-webgui

A lightweight web frontend for LXD
JavaScript
168
star
3

antnium

A C2 framework for initial access in Go
Go
125
star
4

yookiterm-slides

Exploitation and Mitigation Slides
HTML
116
star
5

ffw

A fuzzing framework for network servers
Python
115
star
6

yookiterm-challenges

The challenge writeups and solutions for yookiterm-challenge-files
36
star
7

yookiterm-challenges-files

Challenge files which are deployed in the container for the user
C
23
star
8

avred-server

The AMSI server for Avred
Python
22
star
9

clang-cfi-safestack-analysis

C
21
star
10

antniumui

TypeScript
18
star
11

ace-firefist

Attack chain emulator. Write recipes for initial access easily
Python
14
star
12

rosenbridge

A graphical user interface for Magic Wormhole file transfer
Go
12
star
13

SentinelTestbed

Vulnerable web site. Used to test sentinel features.
PHP
9
star
14

yookiterm-server

Main yookiterm backend
Go
4
star
15

ffw-docker

Docker image of FFW
3
star
16

ffweb

A webgui to view crash information of fuzzing runs (FFW)
Python
3
star
17

tinysploit2-writeup

Solution and writeup for tinysploit2 challenge
Perl
3
star
18

waasa

Windows Application Attack Surface Analyzer
C#
2
star
19

xrop-esp32

Patched xrop to support ESP32 architecture for gadget aquisition
C
2
star
20

nkeyrollover

ASCII side-scrolling beat-em-up game
Python
2
star
21

yookiterm

yookiterm web frontend
JavaScript
2
star
22

yookiterm-lxdserver

Yookiterm LXD backend server
Go
2
star
23

dmsr

Does My Shit Run - Linux Monitoring Solution
Python
2
star
24

ipsctrainor

arduino IPSC trigger trainer
C
1
star
25

ROPNotepadNG

Exploitlab ROPNotepad extended
JavaScript
1
star
26

zeroballistics

JavaScript
1
star
27

xtarget

Python OpenCL project to use with Laser bullets including augmented reality
Python
1
star
28

asanparser

Python
1
star
29

proxybypasser

Bypass proxy download restrictions with JavaScript download
Python
1
star
30

godot-srcvis

Python
1
star