federicodotta / Java-Deserialization-Scanner

All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
776 stars 177 forks source link

Question about Burp and the latest version of the extension #22

Closed halfluke closed 4 years ago

halfluke commented 4 years ago

Hi, just a couple of doubts:

Cheers.

federicodotta commented 4 years ago

Hi @halfluke,

the version is a typo. I will release another version with a fix to the exploitation tab and the version fixed in a few days. Thank you.

About the "Pro extension", it is Burp Suite that labels the extensions as Pro, but I if I'm not wrong you can manually add the jar of all the Pro extensions also in the Community Edition (and all the extensions can be freely downloaded from the GitHub repositories of the authors or from Burp Suite GitHub repository). I think that they label my extensions as "Pro" because it adds some checks to the Active Scanner tool and the scanner is not present in the Community Edition.

Cheers

halfluke commented 4 years ago

Thanks / Grazie Federico!