BurpSentintel – Vulnerability Scanning Plugin For Burp Proxy

Outsmart Malicious Hackers


BurpSentintel is a plugin for Burp Intercepting Proxy, to aid and ease the identification of vulnerabilities in web applications.

Searching for vulnerabilities in web applications can be a tedious task. Most of the time consists of inserting magic chars into parameters, and looking for suspicious output. Sentinel tries to automate parts of this laborous task. It’s purpose is not to automatically scan for vulnerabilities (even if it can do it in certain cases), as there are better tools out there to do that (BURP scanner for example). So it’s the only tool which sits in between manual hacking with BURP repeater, and automated scanning with BURP scanner.

BurpSentintel - Vulnerability Scanning Plugin For Burp Proxy

To use it, just send a suspicious HTTP request from BURP proxy to Sentinel. Then the user is able to select certain attack patterns for selected parameters (say, XSS attacks for parameter “id”). Sentinel will issue several requests, with the attack patterns inserted. It will also help find suspicious behaviour and pattern in the accompaining HTTP responses (for example, identify decoded HTML magic chars).

Features

  • AutomatedDetection Automated XSS/SQL Detection
  • AttackLists Self-Defined Attack Lists
  • Sessions Session Definition
  • Categorizer Categorizer
  • Reporter Generate Report
  • FirefoxAddon Firefox Addon

You can download BurpSentinel here:

BurpPlugin-full.jar

Or read more here.

Posted in: Hacking Tools, Networking Hacking

,


Latest Posts:


snallygaster - Scan For Secret Files On HTTP Servers snallygaster – Scan For Secret Files On HTTP Servers
snallygaster is a Python-based tool that can help you to scan for secret files on HTTP servers, files that are accessible that shouldn't be public and can pose a s
Portspoof - Spoof All Ports Open & Emulate Valid Services Portspoof – Spoof All Ports Open & Emulate Valid Services
The primary goal of the Portspoof program is to enhance your system security through a set of new camouflage techniques which spoof all ports open and also emulate valid services on every port.
Cambridge Analytica Facebook Data Scandal Cambridge Analytica Facebook Data Scandal
One of the biggest stories of the year so far has been the scandal surrounding Cambridge Analytica that came out after a Channel 4 expose that demonstrated the depths they are willing to go to profile voters, manipulate elections and much more.
GetAltName - Discover Sub-Domains From SSL Certificates GetAltName – Discover Sub-Domains From SSL Certificates
GetAltName it's a little script to discover sub-domains that can extract Subject Alt Names for SSL Certificates directly from HTTPS websites which can provide you with DNS names or virtual servers.
Memcrashed - Memcached DDoS Exploit Tool Memcrashed – Memcached DDoS Exploit Tool
Memcrashed is a Memcached DDoS exploit tool written in Python that allows you to send forged UDP packets to a list of Memcached servers obtained from Shodan.
QualysGuard - Vulnerability Management Tool QualysGuard – Vulnerability Management Tool
QualysGuard is a web-based vulnerability management tool provided by Qualys, Inc, which was the first company to deliver vulnerability management services as a SaaS-based web-service.


3 Responses to BurpSentintel – Vulnerability Scanning Plugin For Burp Proxy

  1. Dobin September 4, 2014 at 3:06 pm #

    I’m the author of BurpSentinel. Nice article :-)

    The version in the BApp store is old and obsolete. The URL to BurpPlugin-full.jar is correct. The code is under active development, and I’m always open to feedback.

    • Darknet September 4, 2014 at 4:58 pm #

      Nice work, thanks for dropping a comment :)

  2. Bruno September 4, 2014 at 11:18 pm #

    Nice article, Keep it up! :)