Burp模糊测试---简单扩展工具

from burp import IBurpExtender
from burp import IIntruderPayloadGeneratorFactory
from burp import IIntruderPayloadGenerator

from java.util import List,ArrayList
import random

class BurpExtender(IBurpExtender,IIntruderPayloadGeneratorFactory):
    def registerExtenderCallbacks(self,callbacks):
        self._callbacks = callbacks
        self._helpers = callbacks.getHelpers()
        
        callbacks.registerIntruderPayloadGeneratorFactory(self)
        return
    
    def getGeneratorName(self):
        return "BHP Payload Generator"
    
    def createNewInstance(self,attack):
        return BHPFuzzer(self,attack)

class BHPFuzzer(IIntruderPayloadGenerator):
    def __init__(self,extender,attack):
        self._extender=extender
        self._helpers = extender._helpers
        self._attack = attack
        self.max_payloads = 10
        self.num_iterations = 0
        return
    
    def hasMorePayloads(self):
        if self.num_iterations  == self.max_payloads:
            return False
        else:
            return True
        
    def getNextPayload(self,current_payload):
        payload="".join(chr(x) for x in current_payload)
        payload = self.mutate_payload(pyaload)
        self.num_iterations+=1
        return payload
    
    def reset(self):
        self.num_iterations=0
        return
    
    def mutate_payload(self,original_payload):
        picker = random.randint(1,3)
        offset = random.randint(0,len(original_payload)-1)
        payload=original_payload[:offset]
        
        if picker ==1:
            payload+="'"
            
        if picker ==2:
            payload+="<script>alert('BHP!')</script>"
        
        if picker==3:
            chunk_length=random.randint(len(payload[offset:]),len(payload)-1)
            repeater = random.randint(1,10)
            
            for i in range(repeater):
                payload+=original_payload[offset:offset+chunk_length]
                payload+=original_payload[offset:]
                return payload
  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值