

It is more likely that on an engagement, these keys will not be available. The extension will perform cloud storage tests while doing active scans using these keys. If you have the AWS Access Key and AWS Secret Key, then plug them in and click save. With more and more sites utilizing cloud infrastructure, these types of misconfigurations become more and more important to watch out for. This extension can identify and test S3 buckets, as well as Google Storage buckets and Azure Storage containers, for common misconfiguration issues. Paste the whole Authorization or cookie header into Autorize, including the “Authoriztion:” or “Cookie:” text. Autorize keeps a running list of privileged requests side-by-side with unprivileged ones so you can see at a glance if a low-level user can do things they should not be allowed to do. Now all you have to do is browse the site as an administrator and perform privileged functions. Put those values in Autorize and it will replace then and resend each request it sees with those tokens. Log in as an unprivileged user and grab their session tokens. This plugin allows you to pop-in some session tokens and repeats each request it sees with those tokens. On an average site with 20-30 different administrative functions and a handful of different roles, this type of manual checking could take days.

It has solid performance, a ton of features, and most importantly, extensibility. When doing Web Application Penetration Tests, one tool dominates the desktops of most Security Consultants: Burp Suite Professional ( ).


The Top 8 Burp Suite Extensions That I Use to Hack Web Sites
