Netinfo Security ›› 2016, Vol. 16 ›› Issue (9): 94-97.doi: 10.3969/j.issn.1671-1122.2016.09.019

• Orginal Article • Previous Articles     Next Articles

Burpsuite Extender Apply in Vulnerability Scanning

Shiyuan YU(), Yutian WANG, Xin LIU   

  1. Beijing Public Security Bureau, Beijing 100006, China
  • Received:2016-07-25 Online:2016-09-20 Published:2020-05-13

Abstract:

Burpsuite is a world-renowned leading integrated platform of Web attack, and the platform includes web proxy, web crawler, scanner, automated attack, decoder, repeater and so on.It supports writing custom plugins to extend Burpsuit. In this paper, the work method of Burpsuite tool is studied in depth, and the new method and function of Burpsuite tool is excavated. From the perspective of web security testing, as an example of the popular struts security vulnerabilities, we give full play to the advantages of Burpsuite tools and write a number of Struts vulnerability detection tools.By Burpsuite tool platform,we realize automation Struts vulnerability detection ,identification, and join the coding distortion, to bypass the web application firewall protection means test. And it will play an important role in the safety testing.

Key words: Bupsuite, vulnerability scanning, information security

CLC Number: