PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
606 stars 107 forks source link

Add response.time property #32

Open Sh1Yo opened 1 year ago

Sh1Yo commented 1 year ago

Sometimes it's necessary to compare the times that a server spent for a response so this property will be very useful.

A-J-C commented 1 year ago

Great point, it would open up a whole new avenue for timing based attacks.

mrrootsec commented 1 year ago

Yes please,it would be very helpful in time based attacks detection.

abdilahrf commented 11 months ago

đź‘Ť

ayadim commented 7 months ago

Any news about this enhancement ? until now am creating a bcheck script with time-based payloads but the detection is not possible so am reading the Logger to detect time based issues.

Sh1Yo commented 7 months ago

Remembered this thing after receiving a notification and decided to add a random thought -- maybe solve problems that aren't allowing adding normal scripting like python3 in turbo intruder? The main reason I am not using bchecks and probably won't use it ever is because there's not enough functionality. Moreover, it seems impossible to add every possible function somebody will need.

ayadim commented 7 months ago

for now am using Burp Bount free version to create profiles this do what i want .. Bcheck has big potential to be one of the greate factories to create custom scripts i hope we will see more additions.

Michelle-PortSwigger commented 7 months ago

We're currently working on what will go into the next iteration. We're at the early stages, though, so we can't make any promises yet... we've got quite a few contenders for the time available.

It’s great to hear you’re enjoying using BChecks and want to push them further :)

ayadim commented 7 months ago

Believe me bcheck has great potential to be one of the main functions in burp ... adding other functions to language will makes it powerfull.

Thank you team ,

Regads

ZeeshanDarasa commented 3 months ago

Was creating a DoS detection bCheck for an application known to have DoS issues, need the response.time field

Michelle-PortSwigger commented 3 months ago

Thanks for getting in touch. We'll add your vote for this feature. We don't have any timescales as yet, we're still tracking how many people would find this useful and will use this information to help us prioritize new features.