Introducing DOM invader - A new tool within Burp Suite

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024

Комментарии • 31

  • @-bubby9633
    @-bubby9633 3 года назад +4

    Absolutely fantastic! Finally an easy to use and easy to understand visual tool for finding DOM XSS.

  • @haydene3802
    @haydene3802 3 года назад

    The build poc feature is amazing. Thank you

  • @almokhtar1844
    @almokhtar1844 3 года назад

    really thank you for the nice and easy to understand Explanation

  • @EmilyAnn
    @EmilyAnn 3 года назад

    awesome!! super excited for this! thanks for the very informative video!

  • @slaxblake
    @slaxblake 3 года назад +1

    I have the lasted burp suite pro version but I don't see the tab of "DOM invader" I just see the record tab.

  • @itsignacioportal1728
    @itsignacioportal1728 2 года назад +1

    Incredible work! As always. But consider making the text bigger for future demos. 6px tall text is not easy to read

    • @gazheyes
      @gazheyes 2 года назад +2

      Sorry about that, I’ll try and make sure future videos are more readable. Thanks

  • @GoatSniff
    @GoatSniff 3 года назад +4

    Looks amazing, I was using FileDescriptor's "Untrusted Types" extension for some time.
    Any chance this will make it's way into a standalone browser extension so we don't need to use the burpsuite embedded browser? I have a few other plugins in chrome that I use during bug hunts that I'd rather not lose functionality of, plus the embedded browser runs very poorly on M1 macs, especially anything dev tools related. I think the version of chromium used might not be running natively on M1 macs and instead uses Rosetta :(. Is there a plan for a standalone browser extension not built into the embedded browser?

    • @EmilyAnn
      @EmilyAnn 3 года назад

      Zero chance.
      I have a M1 mac and the embedded browser works seamlessly
      There's zero chance they'd make a stand alone browser extension. That's not their business/. You have 2 options, install those plugins in the embeded browser or use chrome to do those limited checks you want to do with whatever crap chrome plugins you're using...can't honestly think of any that can do something burp can't

    • @GoatSniff
      @GoatSniff 3 года назад +2

      ​@@EmilyAnn Not sure why you're so aggressive about my question?
      Firstly, I'm glad to hear chromium running through Rosetta is fast enough for you, but it isn't for me.
      Second, I don't know why you say there's "zero chance", there are plenty of releases PortSwigger have made for the community that aren't directly related to bringing in revenue. I wasn't aware you were leading up PortSwigger's business strategies.
      Third, I have no idea why you're calling the Untrusted Types plugin "crap", and you might want to look up some of FileDescriptor's work before you badmouth a plugin that DOM invader likely took influence from in the first place. It's a great plugin but I agree DOM invader is even nicer, hence the reason for asking my question in the first place.

  • @hackingismylife2167
    @hackingismylife2167 3 года назад +1

    Absolutely nice your site I like it

  • @angkanchanda1801
    @angkanchanda1801 2 года назад

    got to use this more often.

  • @shrimantmore7765
    @shrimantmore7765 2 года назад

    Nice, but I could barely see anything. It would be great if you could increase the font size for burp suite and browser and other tabs

  • @gurudattchoudhary
    @gurudattchoudhary 11 месяцев назад

    my browser not showing this extension not even in extension option how to download how can i do it

  • @waliulahmed9582
    @waliulahmed9582 3 года назад

    This is soo cool.

  • @Stas1983ful
    @Stas1983ful 2 года назад

    All wark, but Inject URL button add canary to url, but plugin don't catch vulnerability :(

  • @Umar0x01
    @Umar0x01 2 года назад

    Thanks!

  • @indiantechnical69
    @indiantechnical69 3 года назад

    Superb😍😍

  • @takeshikovacs667
    @takeshikovacs667 3 года назад +1

    It would be nice to have video timestamps.

  • @formularyzer
    @formularyzer 2 года назад

    How do I get hold of outer HTML payloads?

    • @gazheyes4894
      @gazheyes4894 2 года назад

      At the moment you have to inspect the desired element using devtools. We plan to show the outerHTML in the augmented DOM in future.

  • @pt5235
    @pt5235 3 года назад

    Brilliant! I was using Tracy extension for this purposes but its a bit buggy and definitely not that powerful!

    • @EmilyAnn
      @EmilyAnn 3 года назад

      me too. This tool will be awesome

  • @Alex-xb8yo
    @Alex-xb8yo 10 месяцев назад

    thanks, but please make the font bigger next time

  • @sarcasmco1155
    @sarcasmco1155 3 года назад

    How to find the extension !!i updated but did not found just the recorder there!Thanks

    • @Alex-td4jt
      @Alex-td4jt 3 года назад

      Have you followed the guide? portswigger.net/blog/introducing-dom-invader You need to be on the Early Adopter channel, and it is within the Burp Container Extension

  • @hahwul
    @hahwul 3 года назад

    A w e s o m e 😄

  • @shuvamadhikari2662
    @shuvamadhikari2662 3 года назад

  • @cravenmoorehead5657
    @cravenmoorehead5657 Год назад

    Yes dom daddy