Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
This adds inverse enforcement detector filters (for both authentication and authorization enforcement) that allow to detect a message as enforced if some condition is not fulfilled.
Example: Use type "Body NOT (simple string)" to flag messages as enforced if their response body does not contain some string.
This adds inverse enforcement detector filters (for both authentication and authorization enforcement) that allow to detect a message as enforced if some condition is not fulfilled.
Example: Use type "Body NOT (simple string)" to flag messages as enforced if their response body does not contain some string.