03 September 2014 | 2,992 views

BurpSentintel – Vulnerability Scanning Plugin For Burp Proxy

Check Your Web Security with Acunetix

BurpSentintel is a plugin for Burp Intercepting Proxy, to aid and ease the identification of vulnerabilities in web applications.

Searching for vulnerabilities in web applications can be a tedious task. Most of the time consists of inserting magic chars into parameters, and looking for suspicious output. Sentinel tries to automate parts of this laborous task. It’s purpose is not to automatically scan for vulnerabilities (even if it can do it in certain cases), as there are better tools out there to do that (BURP scanner for example). So it’s the only tool which sits in between manual hacking with BURP repeater, and automated scanning with BURP scanner.

BurpSentintel - Vulnerability Scanning Plugin For Burp Proxy

To use it, just send a suspicious HTTP request from BURP proxy to Sentinel. Then the user is able to select certain attack patterns for selected parameters (say, XSS attacks for parameter “id”). Sentinel will issue several requests, with the attack patterns inserted. It will also help find suspicious behaviour and pattern in the accompaining HTTP responses (for example, identify decoded HTML magic chars).

Features

  • AutomatedDetection Automated XSS/SQL Detection
  • AttackLists Self-Defined Attack Lists
  • Sessions Session Definition
  • Categorizer Categorizer
  • Reporter Generate Report
  • FirefoxAddon Firefox Addon

You can download BurpSentinel here:

BurpPlugin-full.jar

Or read more here.



Recent in Hacking Tools:
- masscan – The Fastest TCP Port Scanner
- drozer – The Leading Security Testing Framework For Android
- tinfoleak – Get Detailed Info About Any Twitter User

Related Posts:
- Burp Proxy & Burp Suite – Attacking Web Applications
- Paros Proxy 3.2.11 Released – MITM HTTP and HTTPS Proxy
- Paros Proxy 3.2.10 Released – MITM HTTP and HTTPS Proxy

Most Read in Hacking Tools:
- Top 15 Security/Hacking Tools & Utilities - 1,869,552 views
- Brutus Password Cracker – Download brutus-aet2.zip AET2 - 1,059,974 views
- wwwhack 1.9 – Download wwwhack19.zip Web Hacking Tool - 624,846 views

Low-cost VPS Hosting

3 Responses to “BurpSentintel – Vulnerability Scanning Plugin For Burp Proxy”

  1. Dobin 4 September 2014 at 3:06 pm Permalink

    I’m the author of BurpSentinel. Nice article :-)

    The version in the BApp store is old and obsolete. The URL to BurpPlugin-full.jar is correct. The code is under active development, and I’m always open to feedback.

  2. Bruno 4 September 2014 at 11:18 pm Permalink

    Nice article, Keep it up! :)


Leave a Reply