
Burp Beautifier: BurpBeautifier is a Burpsuite extension for beautifying request/response body, supporting JS, JSON, HTML, XML format, writing in Jython 2.7.ħ. Autorize Burp: Autorize is an extension aimed at helping the penetration tester to detect authorization vulnerabilities-one of the more time-consuming tasks in a web application penetration test.Ħ. Autorepeater Burp: Automated HTTP request repeating with Burp Suite.ĥ. It's easy to find low-hanging fruit and hidden vulnerabilities like this, and it also allows the tester to focus on more important stuff!Ĥ. Not only that, but it also shows a lot of information of the HTTP responses, corresponding to the attack requests. BurpSentinel: With BurpSentinel it is possible for the penetration tester to quickly and easily send a lot of malicious requests to parameters of a HTTP request. Designed to add minimal network overhead, it identifies application behavior that may be of interest to advanced testers.ģ. ActiveScan++: ActiveScan++ extends Burp Suite's active and passive scanning capabilities. Once you hit 500 reputation on HackerOne, you are eligible for a free 3-month license of Burp Suite Pro! Check out these awesome Burp plugins:Ģ.

Burp Suite: The quintessential web app hacking tool.

Check them out to add to your own hacking toolkit! We’ll add these to our GitHub on Hacker101/_resources/ so feel free to continue adding even more tools and resources!ġ.

As we recently surpassed $100 million dollars in bounties, we want to continue the celebration with this list of 100 tools and resources for hackers! These range from beginner to expert.
