Using Param Miner to Discover Parameters in Burp Suite

Поделиться
HTML-код
  • Опубликовано: 21 авг 2024
  • Param Miner is great because it's simple to use, but also provides great coverage when attempting to discover hidden web application parameters.
    ▬▬ Video Resources ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
    Param Miner GitHub: github.com/Por...
    Unofficial Param Miner Docs: github.com/nik...
    ▬▬ Follow Me ▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬▬
    My blog: ryarmst.ca/ind...
    LinkedIn: / ryarmst
    Twitter: / ryarmst

Комментарии • 9

  • @jayseb
    @jayseb 3 месяца назад

    I've been using Burp for 20 years and there's always something we can learn. Cheers.

    • @ankitraj779
      @ankitraj779 2 месяца назад

      can u help me for a website

  • @mirhassanriaz7713
    @mirhassanriaz7713 8 месяцев назад +3

    Your work is superb, I didn't find any better channel than this to understand the niches of burp extensions and specialized use-cases. Keep up the amazing work!

    • @Ryan_Armstrong
      @Ryan_Armstrong  8 месяцев назад

      Thank you very much. More coming soon.

  • @simunricov6513
    @simunricov6513 10 месяцев назад +1

    Can I slow down Param Miner to 1 request per second

    • @Ryan_Armstrong
      @Ryan_Armstrong  10 месяцев назад

      I too had this problem once! You can use the Distribute Damage extensions: ruclips.net/video/gMELf8U8OkE/видео.html

  • @user-dx1eq3vf5b
    @user-dx1eq3vf5b 9 месяцев назад

    I'm not sure if this tool is useful because I've never discovered anything interesting using it. In my view, when you get a certain interface, the response data must have already been obtained by you. So, fuzzing known interface data is meaningless. Time should be spent on finding unauthorized interfaces.

    • @user-dx1eq3vf5b
      @user-dx1eq3vf5b 9 месяцев назад

      The official definition of the tool is to discover cache poisoning vulnerabilities.

    • @rarmst2
      @rarmst2 9 месяцев назад

      @@user-dx1eq3vf5b The tool is designed to identify unknown request parameters and can also identify cache poisoning vulns. I have discovered worthwhile findings with it, but they are not very common.