PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
606 stars 107 forks source link

Added Multiple Templates for Laravel & Symfony Frameworks Misconfigurations #41

Closed yasinyilmaz closed 1 year ago

yasinyilmaz commented 1 year ago

Summary: Symfony and Laravel based applications, like many similar frameworks it includes a diferrent debug modes with a special interface, allowing developers to view the internal state of network connections for the purpose of identifying errors and misconfigurations, before going production. If debug mode enabled, some systems show the full details of cleartext HTTP request, responses, passwords, tokens and app secrets in debug mode.

References:

michael-eaton-portswigger commented 6 months ago

@yasinyilmaz As a contributor to our GitHub repository, we would like to invite you to our closed Discord community.

It is a place where passionate Burp users, including people who directly work on building and developing Burp here at PortSwigger, can talk about the tooling and web security in general.

If you would like to join, please email us at support@portswigger.net and we will send over an invite link.

Thank you!