


It was written in Python by Barak Tawily, an application security expert, and Federico Dotta, a security expert at. AutorizeĪutorize is an automatic authorization enforcement detection extension for Burp Suite. Be sure to use Jython version 2.7.0 or greater to ensure compatibility. These tables are structured in a similar format to that of an access control matrix common in various threat modeling methodologies.ĪuthMatrix requires configuring Burp Suite to use Jython. With AuthMatrix, testers focus on thoroughly defining tables of users, roles, and requests for their specific target application upfront. AuthMatrixĪuthMatrix is an extension to Burp Suite that provides a simple way to test authorization in web applications and web services. Of all the integrated tool suites, Burp is the only one that implements a fully functional web application spider, which parses forms and JavaScript, and allows automated and user-guided submission of form parameters.īelow we’ve listed out the top 19 plugins which are open source and can be integrated under Burp as an extenders which are as follows: 1. The proxy can also be configured to perform automated matching and replacement of message headers, and provides an in-browser interface for viewing the proxy cache and reissuing individual requests. Its proxy function allows configuration of very fine-grained interception rules, and clear analysis of HTTP messages structure and contents. Burp is highly functional and provides an intuitive and user-friendly interface. Burp Suite is an intercepting HTTP Proxy, and it is the defacto tool for performing web application security testing.
