Using Burp Suite extensions for bug bounties
As bug bounty hunters, you will find handy tools to identify possible bugs more easily. There are many, but the two we will look at in this recipe are the Burp Bounty, Scan Check Builder and Auth Analyzer.
Note
Burp Bounty, Scan Check Builder requires the Burp Suite Professional version.
Getting ready
Both recommended extensions for bug bounty hunting can be found in the BApp Store subtab. We will download and install them within our Burp Suite instance. Then, we’ll see how to use each to potentially uncover bugs for payouts!
How to do it...
- Inside Burp Suite’s Extensions | BApp Store tab, select Burp Bounty, Scan Check Builder and click the Install button. Then, select Auth Analyzer and click the Install button:
Figure 10.55 – The two extensions covered in this recipe
- Switch to the Extensions | Installed tab and ensure both extensions are installed and enabled...