Giter Site home page Giter Site logo

manlio-tapia / dr.-watson Goto Github PK

View Code? Open in Web Editor NEW

This project forked from prodigysml/dr.-watson

0.0 1.0 0.0 46 KB

Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's your very own discovery side kick, the Dr. Watson to your Sherlock!

Python 100.00%

dr.-watson's Introduction

Dr. Watson

Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's your very own discovery side kick, the Dr. Watson to your Sherlock!

License Twitter

How Does Dr. Watson Work?

Dr. Watson takes regexes from the issues_library.json file and attempts to match said regexes with responses within Burp Suite. Once it matches a regex, it raises an issue with the severity defined in the config, as a finding for the target host. It is simple, sweet, and easy to use!

Setup - Installing for Burp Suite Pro

Setting Up Jython

  1. Download the latest standalone version of jython
  2. Navigate to Extender -> Options
  3. Navigate to the "Python Environment" section
  4. Click "Select File" and select the previously downloaded file

Installing the Plugin

  1. Navigate to Extender -> Extensions
  2. Click the "Add" button
  3. Change the "Extension Type" to "Python"
  4. Select the plugin python file within the "Extension file" field
  5. Click "Next"
  6. Enjoy the plugin!

How to Use The Plugin

  1. Install the plugin
  2. Add any domain you want analysed into scope (if not in scope, it will not be analysed, ensuring performance is not hindered immensely)
  3. Navigate / crawl through the website and observe the plugin creates issues for different resources identified.

Authors and Thanks

Originally written by Sajeeb Lohani (sml555). I would like to thank the following for helping with the project:

  • BugCrowd HUNT for the Jython installation steps
  • Redhunt Labs for the original plugin and the idea
  • TruffleHog Regexes and git-all-secrets for the regexes

Contributions

Contributions to this project are very welcome. If you're a newcomer to open source and would like some help in doing so, feel free to reach out to me on twitter (@sml555_) and I'll assist wherever I can.

dr.-watson's People

Contributors

jeffhacks avatar jgerardos avatar prodigysml avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.