Introduction to BurpFingerPrint
During the attack, we usually use the browser to access some assets. This BurpSuite plug-in implements passive fingerprint recognition + website link extraction + OA blasting, which can help us discover more assets. CMS identification.The functions are as follows
The following functions will be completed by the end of May 2024. If you have better suggestions, please feel free to give me a Star. It is not easy to create. We will create the strongest fingerprint recognition library and weak password detection library.
- Browser passive fingerprint recognition, integrated with Ehole fingerprint recognition library
- Extract the URL link of the website and parse the URL link in the JS file for fingerprint recognition
- Open the interface to modify the fingerprint library, which can be imported, exported, and reset
- Optimize the existing fingerprint library, distinguish between key fingerprints and common fingerprints, add fingerprints of some popular vulnerabilities in actual combat, and facilitate one-click getshell
Support fingerprint detection
- Tongda OA
- Zhiyuan OA
- Lanling OA
- Fanwei OA
- Wanhu OA
- Donghua OA
- OA
- etc.
Support weak password cracking components in the future
- Tongda OA
- Zhiyuan OA
- Lanling OA
- Fanwei OA
- Wanhu OA
- Donghua OA
- OA
Disclaimer
This tool is only used for security research and communication, please do not use it for illegal purposes. If you commit any illegal acts while using this tool, you will bear the consequences yourself, and I will not bear any legal and joint liability.
Historical update records
BurpFingerPrint fingerprint recognition v1.2
- Open fingerprint recognition custom configuration page
- Support front-end fingerprint switch, key fingerprint switch and all fingerprint switches
- Optimize the display page to support filtering of key fingerprints and Type types in the results
- Added 56 key fingerprint databases
BurpFingerPrint fingerprint recognition v1.1
- Optimize the code, filter the URLs extracted from the web pages and JS codes, and remove the previously processed ones related to the domain name
- Optimize code and increase the number of concurrent fingerprint recognition
- Optimize the code and display the GUI to quickly filter fingerprint tags
- Optimize code and solve the problem of garbled Chinese display
BurpFingerPrint fingerprint recognition v1.0
- Browser passive fingerprint recognition, integrated with Ehole fingerprint recognition library
- Match IP/domain name/link on the website for fingerprint matching