PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
619 stars 109 forks source link

Add detection of SameSite disabled #126

Closed righettod closed 1 year ago

righettod commented 1 year ago

Hello,

This PR propose a script to detect when a cookie disable the SameSite protection by setting the value to None.

The objective of the script is to raise a information notice to allow to investigate to see if an CSRF attack can be used due to this settings.

Thanks you very much in advance for your feedback 😃

righettod commented 1 year ago

Hi @PortSwiggerWiener,

Thanks a lot for your feedback, I applied all your feedback.

Feel free to reach if I missed something 😃

righettod commented 1 year ago

You are welcome, thanks for the review.

righettod commented 1 year ago

Thank you very much 😃

michael-eaton-portswigger commented 7 months ago

@righettod As a contributor to our GitHub repository, we would like to invite you to our closed Discord community.

It is a place where passionate Burp users, including people who directly work on building and developing Burp here at PortSwigger, can talk about the tooling and web security in general.

If you would like to join, please email us at support@portswigger.net and we will send over an invite link.

Thank you!