benteveo-kiwi / benteveo-toolbox

A burp extension that allows for IDOR testing and facilitates automatic scanning.
1 stars 0 forks source link

Automate spidering? #17

Open SamJoan opened 4 years ago

SamJoan commented 4 years ago

Some folks at yandex have automated spidering and documented their approach, which I think is feasible for us and similar to what I had in mind.

https://2017.zeronights.org/wp-content/uploads/materials/ZN17_Zaitov_Automation%20of%20Web%20Application%20Scanning%20with%20Burp%20Suite.pdf

SamJoan commented 4 years ago

Here are their de-duplicating strategies which I think are very impressive; https://github.com/yandex/burp-molly-scanner/tree/master/src/main/java/deduper