How to use the Burp plug-in Unexpected_information
Burp plug-in Unexpected_information how to use, I believe that many inexperienced people do not know what to do, so this article summarizes the causes of the problem and solutions, through this article I hope you can solve this problem.
Author: xiaowei
Team: Timeline Sec
Email: xiaowei@timelinesec.com recently wrote a BurpSuite Extensions to mark sensitive information, JS interfaces, and special fields in the request packet to prevent us from neglecting some packets. I named it "Unexpected information", and using it may have unexpected information. Introduce the support list
ID card information
Mobile phone number information
IP information
Mailbox information
JS file API interface path
Special fields (password, method: "post"...)
Two-way detection
Highlight
Highlight mode mailbox-> yellow
Private network IP-> red
Mobile phone number-> Green
ID card number-> green
Other-> none (only open Unexpected information tab)
When there is relevant corresponding information in the packet (such as mobile phone number, IP address, mailbox, ID number, etc.), the corresponding request in the HTTP history tab is automatically highlighted, and a new tab named "Unexpected information" is opened to display the matching information. How to use BurpSuite > > Extender > > Extensions > > Add > > Extension type: Java > > Select file... > > Select the corresponding plug-in (Unexpected information.jar) Note: avoid using Chinese directories
Effect.
After reading the above, have you mastered how to use the Burp plug-in Unexpected_information? If you want to learn more skills or want to know more about it, you are welcome to follow the industry information channel, thank you for reading!