PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
606 stars 107 forks source link

Added Multiple CVE and Misconfiguration Templates #50

Closed Parimal-shaw closed 1 year ago

Parimal-shaw commented 1 year ago

Added Following Templates:

olliewuk commented 1 year ago

in other/Apache Tomcat Manager Path Normalization Panel.bcheck should the password be static as it is?

Parimal-shaw commented 1 year ago

Yes, it doesn't disclose current users password a user can change whatever they want the password to be .

olliewuk commented 1 year ago

Yes, it doesn't disclose current users password a user can change whatever they want the password to be .

Should the check be modified in that case to not include a specific password?

Parimal-shaw commented 1 year ago

Not required , the current check cannot be changed in any other way the following checks required a password in static form or else the password will get rejected .

Parimal-shaw commented 1 year ago

All the changes have been done ,suggested by you