ATOR – Authentication Token Obtain and Replace – Burp Suite plug-in for complex session mechanisms

Come on burp suite tool has a built-in session mechanism, more and more often I meet situations where i just can not cope with keeping it active. This is most often caused by one of the following factors: Dynamic CSRF tokens hidden in different places of the request; JavaScript-based applications… Continue reading

Hidden content – do you know what to look for? Ready good dictionary.

Enumeration tools such as DIRB require a specially prepared dictionary that sometimes contains hundreds of thousands of the most common folder and file names. It's technologies are constantly changing, and with them the paths to seemingly hidden content. In order to successfully carry out enumeration attacks, you need to complete… Continue reading