Federico Dotta retweeted
Introducing Burp AT. Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. Now live in public beta for Burp Suite Professional users. portswigger.net/blog/introdu…
10
53
113
36,199
To wrap up @Burp_Suite Extensibility Month initiatives, I just released AI Reporter, a Burp Suite extension that brings AI-powered automation to penetration test reporting using Burp AI or a local Ollama instance. More details: hnsecurity.it/blog/ai-report…
1
3
4
416
As part of @Burp_Suite Extensibility Month initiatives, last week I gave a talk titled “Restoring testability: Handling complex scenarios in Burp Suite with a custom extension”. Video, slides and code can be found here: hnsecurity.it/blog/restoring…
3
12
3,713
Federico Dotta retweeted
🚀 Want to build your own Burp Suite extensions? As part of Burp Extensibility Month, we’re sharing Burp Ambassador Federico Dotta's (@apps3c) 10-part guide to extending Burp Suite with the Montoya API. Start here 👇 hnsecurity.it/blog/extending… #BurpSuite #BurpExtensibility
3
3
16
2,441
I’ll be hosting a live session during @Burp_Suite Extensibility Month on the @PortSwigger Discord on May 14 at 4 PM BST / 5 PM CEST. Topic: “Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension”. Join us live! discord.gg/portswigger?event…
1
4
122
To celebrate the @Burp_Suite Extensibility Month, the tenth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! The topics of this tenth part is "Burp AI"! Stay tuned for a new extension on the topic on @BApp_Store! hnsecurity.it/blog/extending…
4
8
2,967
Federico Dotta retweeted
Highlights include: ✨ Our new Burp Ambassadors, @apps3c and @0xTib3rius, present sessions covering creating custom extensions for complex testing scenarios and a Bambda generation framework. 🔬 A deep dive with PortSwigger researcher @zakfedotkin on vibecoding Burp extensions.
1
2
9
1,542
Federico Dotta retweeted
🚀 Extensibility Month is launching on the PortSwigger Discord! Join us for a month of events, resources, and community discussion all about creating, sharing, and getting more from Extensibility in Burp Suite. #BurpSuite #BurpExtensibility
1
5
17
3,737
Federico Dotta retweeted
Meet the Burp Ambassadors: @apps3c 🇮🇹 Federico Dotta is an offensive security researcher with a deep focus on Burp Suite extensibility. #BurpAmbassador #BurpSuite #BurpExtensibility #BApps
2
5
45
4,761
The ninth article of the series "Extending Burp Suite for fun and profit - The Montoya way" is out! The topics of this ninth part is "Custom scan checks - An improved quick way to extend Burp Suite Active and Passive Scanner"! hnsecurity.it/blog/extending…
2
204
Federico Dotta retweeted
🔄 Brida, Burp to Frida Bridge A bridge between Burp Suite and Frida to help test Android applications. 👇 portswigger.net/bappstore/2c…
1
2
2
289
I released an updated version of Brida (0.6), fully compatible with @fridadotre >= 17! You can download the new release from GitHub and soon from the @Burp_Suite BAppStore. hnsecurity.it/blog/brida-0-6…
2
6
282
A few notes and examples on a topic I've been exploring recently: AI red teaming on LLM-based applications! security.humanativaspa.it/at…
3
5
373
Federico Dotta retweeted
The unattainable unicorn in fault injection! Our latest article reveals that single-bit faults are possible on ESP32. Discover how some bits are easier to flip and why lowest voltage isn't always best. Join @0x696e6f6465 in his #hardwarehacking quest. security.humanativaspa.it/fa…
5
6
858
Eighth article of the series "Extending @Burp_Suite for fun and profit - The Montoya way" is out! Topic: BChecks - A quick way to extend Burp Suite Active and Passive Scanner! security.humanativaspa.it/ex…
4
7
968
Seventh article of the series "Extending @Burp_Suite for fun and profit - The Montoya way" is out! Topic: using the Collaborator in Burp Suite plugins! security.humanativaspa.it/ex…
1
8
918
Great article on fault injection by my colleague @0x696e6f6465. Definitively worth a read! security.humanativaspa.it/fa…
147
Federico Dotta retweeted
Display responses that came from a server-side cache (Varnish/Cloudfront) with this filter bambda: return requestResponse.response().headerValue("X-Cache").toLowerCase().contains("hit");
10
93
8,775
Sixth article of the series "Extending @Burp_Suite for fun and profit - The Montoya way" is out! Topic: adding new checks to Burp Suite Active and Passive Scanner! security.humanativaspa.it/ex…
4
12
813
Federico Dotta retweeted
Replying to @InsiderPhD
4. Brida, Burp to Frida bridge Bridges Burp and Frida, enabling traffic manipulation across multiple platforms. Simplifies mobile testing with direct function usage for data encryption/decryption, offering custom plugins, tabs, menu options and more. portswigger.net/bappstore/2c…
3
30
3,201