PortSwigger / backslash-powered-scanner

Finds unknown classes of injection vulnerabilities
Other
641 stars 93 forks source link

Support for JSON parameters #24

Closed ghost closed 2 years ago

ghost commented 2 years ago

Great tool.

Will there be support for JSON endpoints. Scanning with the latest version of the scanner with Burp doesn't issue any request.

albinowax commented 2 years ago

If you use Burp's scan engine (IE right click-> do active scan) it should work fine. Integrated support for bulk scanning JSON might land at some point but it's not a short term priority.

ghost commented 2 years ago

Last question, will here be support of injecting a custom marker to scan with the scanner just like Turbo Intruder?

albinowax commented 2 years ago

You can do this currently by using 'Scan defined insertion points' in the Intruder, and disabling non-extension scanchecks.