PortSwigger / BChecks

BChecks collection for Burp Suite Professional and Burp Suite Enterprise Edition
https://portswigger.net/burp/documentation/scanner/bchecks
GNU Lesser General Public License v3.0
619 stars 109 forks source link

Add "given hostpath then" attribute. #67

Closed JaveleyQAQ closed 1 year ago

JaveleyQAQ commented 1 year ago

Add "given hostpath then" attribute. If only supports request and host functions scanners like nuclei can easily achieve this and have complete poc templates. Bcheck does not have an advantage. It should utilize the crawling advantage to scan discovered secondary and tertiary paths, instead of only being able to scan first-level vulnerability paths like nuclei.

A-J-C commented 1 year ago

Try watching the YouTube video to see how to achieve this. BChecks fully utilises the underlying crawl and scan engine.