Working with the Active Scan++ extension
Some extensions assist in finding vulnerabilities with specific payloads, such as XML, or help to find hidden issues, such as cache poisoning and DNS rebinding. In this recipe, we will add an active scanner extension called Active Scan++, which assists with identifying these more specialized vulnerabilities.
Note
This plugin requires the Burp Suite Professional edition.
Getting ready
Using the OWASP Mutillidae II application, we will add the Active Scan++ extension, and then run an active scan against the target.
How to do it...
- Switch to Burp Suite’s Extensions | BApp Store tab and select the Active Scan++ extension. Click the Install button to install the extension, as follows:
Figure 10.52 – Active Scan++ extension
- Return to the Firefox browser and browse to the Mutillidae home page.
- Switch to Burp Suite’s Target tab and then the Site map subtab, right...