-
Notifications
You must be signed in to change notification settings - Fork 27
Installation
matthewD-AVI edited this page Feb 21, 2019
·
9 revisions
- Download and install the latest build of PortSwigger BurpSuite from http://portswigger.net/burp/
- Scanner functionality available.
- The plugin will run source code analysis and seed endpoints into the target sitemap, and optionally run the spider and active scanning functionality.
- Scanner unavailable
- Plugin will run source code analysis and send seeded endpoints to Target and Spider; Scanner will not run
- Download latest Attack Surface Detector Burp addon file from https://github.com/secdec/attack-surface-detector-burp/releases
- Launch Burp
- Navigate to the Extender tab
- Click Add in Burp Extensions section
- In the popup, browse to attacksurfacedetector-release-#.jar (Note: The plugin file must be named attacksuracedetector-release-#.jar, where "#" is some number. This should be the default name when you download/grab the plugin.)
- Click Open
- Notice a new tab should now be available Attack Surface Detector
- Download and install the latest version of Burp
- Launch Burp
- Select the 'Extender' tab
- Select the 'BApp Store' sub tab
- Select 'Attack Surface Detector'
- Click install
- Notice a new tab should now be available Attack Surface Detector