• Stars
    star
    238
  • Rank 165,365 (Top 4 %)
  • Language
    Python
  • Created about 4 years ago
  • Updated almost 4 years ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage.

Xkeys (BurpSuite Extension)

Description

A Burp Suite Extension to extract interesting strings (key, secret, token, or etc.) from a webpage. and lists them as information issues.

Type : Passive Scanner

Setup

  • Setup the python environment by providing the Jython.jar file in the 'Options' tab under 'Extender' in Burp Suite.
  • Download the BurpSuite-Xkeys.zip.
  • In the 'Extensions' tab under 'Extender', select 'Add'.
  • Change the extension type to 'Python'.
  • Provide the path of the file "Xkeys.py" and click on 'Next'.

Usage

  • The extension will start identifying assets through passive scan.

Result

  • The extension will show on issues box and on output extender

Possible Value Extraction

{keyword}=<value>
{keyword}= <value>
{keyword} =<value>
{keyword} = <value>
{keyword}'='<value>'
{keyword}'= '<value>'
{keyword}' ='<value>'
{keyword}' = '<value>'
{keyword}"="<value>"
{keyword}"= "<value>"
{keyword}" ="<value>"
{keyword}" = "<value>"
{keyword}":"<value>"
{keyword}": "<value>"
{keyword}" :"<value>"
{keyword}" : "<value>"
{keyword}=<value>&

Requirements

Code Credits:

# PortSwigger example-scanner-checks: https://github.com/PortSwigger/example-scanner-checks
# RedHuntLabs BurpSuite-Asset_Discover: https://github.com/redhuntlabs/BurpSuite-Asset_Discover
  • Sec7or Team
  • Surabaya Hacker Link

More Repositories

1

xkeys

Extract Sensitive Keys, Secret, Token Or Interested thing from source
Go
49
star
2

DiscordSelfbot

Simple Discord SelfBot Python Version
Python
47
star
3

Command-Collections

Simple command shell collections
Shell
34
star
4

Laravel-PhpUnit-Rce-And-Get-Env-Exploiter

Laravel PhpUnit Rce And Get Env Exploiter
Shell
23
star
5

0x-Wallet-Generator

ERC20 BEP20 Wallet Generator
JavaScript
22
star
6

gitdorkhelper

Just simple helper tool for generate github search link
Shell
16
star
7

DOSI

Auto Claim DON + Participate Adventure DOSI
Python
15
star
8

urlive

Check url is live (*HTTP status code "200 ok" only*).
Go
14
star
9

twitdrop

Airdrop Twitter Task Helper (Follow, Like, Retweet Quote)
PHP
13
star
10

xurls

eXtract URLs from source
Go
10
star
11

Email-Opened-Tracker

Email Opened Tracker
PHP
9
star
12

Sol-Wallet-Generator

Solana Wallet Generator
JavaScript
8
star
13

DC-Bot-Auto-Post

Python
8
star
14

discrot

Discrot is a simple GO tool for Grinding / Leveling chat discord
Go
8
star
15

cXss

Capture XSS
PHP
7
star
16

bigtoken

Big Token Auto Register And Verification
Shell
6
star
17

Discord-SelfBot

Simple Discord Self Bot
JavaScript
5
star
18

PUBGM-UserCustom-En-Decoder

PHP
5
star
19

Discord-Selfbot-Google-Script

Discord Selfbot Google App Script
JavaScript
5
star
20

vsec7.github.io

HTML
4
star
21

Simple-CRUD-with-jsonstore.io

Create, Read, Update, Delete with jsonstore.io
PHP
4
star
22

Simple-MySQL-Injection-Labs

Simple Labs MySQL Injection
PHP
4
star
23

dirscans

Web File / Directory Scanner
Shell
3
star
24

Dump-The-Flag-Source

PHP
3
star
25

qriket

Qriket Auto Claim Spin Balance
Shell
3
star
26

Auto-Claim-Hi-Tele-SelfBot

Auto Claim Hi.com Telegram SelfBot
Python
3
star
27

MassTweet

Simple Mass Tweet (follow, Like, RT, Reply, Quote)
Python
3
star
28

Simple-Google-Dorker

PHP
2
star
29

DCBot-On24x7

Python
2
star
30

Simple-Email-Sorter

Shell
2
star
31

Yahoo-Email-Exist-Checker

Shell
2
star
32

mass-join-leave-discord-selfbot

Simple Mass Join Leave Discord Selfbot
JavaScript
2
star
33

GoSex

Simple GoPay Sender
Shell
2
star
34

Reverse-IP-And-Dtect-CMS

Reserve IP And Detect CMS
Shell
2
star
35

vsec7

2
star
36

phrase2pk

Seed phrase / Mnemonic to Private key Converter tool for Ethereum Wallet
TypeScript
1
star
37

threads-bot

Auto posts random quote threads.net
JavaScript
1
star
38

NeverBounce-Checker-Bash-

Never Bounce Email Valid Checker
Shell
1
star
39

nft-list

NFT Name Lists
1
star
40

Compare-2-Files

Shell
1
star
41

Extract-data-with-SQLi-curl-grep-

1
star
42

Simple-API-dunia21-Scrapper

PHP
1
star
43

Auto-Claim-Hi

Auto Claim Hi.com
JavaScript
1
star
44

revip

Reverse IP Domain Checker
Go
1
star
45

Mnemonic2PK

Mnemonic to PrivateKey Converter
JavaScript
1
star
46

Mass-Join-Leave-DC-Selfbot

Mass Join Leave DC Selfbot Python version
Python
1
star
47

Simple-WP-Auto-Login-And-Shell-Upload

Shell
1
star
48

rincans.io

my cans
JavaScript
1
star
49

SAMEHADAKU.NET-GRABBER-API

SAMEHADAKU GRABBER API
PHP
1
star
50

Contoh-Auto-Login-Dan-File-Upload

Shell
1
star
51

botwarpcast

Auto Following Warpcast (Farcaster)
1
star