Giter VIP home page Giter VIP logo

moeinfatehi / backup-finder Goto Github PK

View Code? Open in Web Editor NEW
151.0 1.0 29.0 279 KB

A burp suite extension that reviews backup, old, temporary and unreferenced files on web server for sensitive information (OWASP WSTG-CONF-04, OTG-CONFIG-004)

License: GNU General Public License v3.0

Java 100.00%
application-security appsecurity burp burp-extensions burpsuite burpsuite-extender owasp penetration-testing pentesting portswigger

backup-finder's Introduction

๐Ÿ‘‹ Hi there, I'm Moein Fatehi!

Experienced Cybersecurity Specialist and Team Leader, specializing in vulnerability assessment and penetration testing. Passionate about blockchain security and fintech innovations. Developer of a sophisticated cryptocurrency trading bot and founder of VAaaS for smart contract vulnerability detection. Active in CTF competitions with multiple first-place wins as part of the DCUA team. Committed to driving security advancements in both traditional and blockchain technologies. Welcome to my GitHub page where I share my projects and contributions to the world of cybersecurity and blockchain.

Twitter: MoeinFatehi Linkedin: MoeinFatehi GitHub MoeinFatehi

๐ŸŒŸ My Projects

Here's a glimpse of my work:

BurpSuite Extensions

  • Backup-Finder: A Burp Suite extension that dynamically reviews backup, old, temporary, and unreferenced files on web servers for sensitive information. Technologies: Java, Gradle. GitHub stars GitHub forks
  • Admin-Panel_Finder: Enumerates infrastructure and application Admin Interfaces with configurable testing levels. Technologies: Java, Gradle. GitHub stars GitHub forks
  • CVSS_Calculator: Offline CVSS v2 and v3.1 scores calculator with a user-friendly interface. Technologies: Java. GitHub stars GitHub forks
  • PassiveDigger: Passive analysis of web traffic for vulnerabilities, with features like request and response checks. Technologies: Java, Gradle. GitHub stars GitHub forks

Vulnerable Web Challenges

  • xss_vulnerability_challenges: XSS vulnerability challenges in a Dockerized PHP application, focusing on various bypass techniques. Technologies: PHP, Docker. GitHub stars GitHub forks
  • file_upload_vulnerability_scenarios: Challenges related to file upload vulnerabilities, including various bypass techniques. Technologies: PHP, Docker. GitHub stars GitHub forks
  • lfi-to-rce-scenario: LFI to RCE vulnerability challenges in a Dockerized environment, demonstrating path traversal and command execution. Technologies: PHP, Docker. GitHub stars GitHub forks
  • captcha_logical_bypass_scenarios: Captcha logical bypass challenges, exploring various techniques to circumvent captcha protections. Technologies: PHP, Docker. GitHub stars GitHub forks
  • rfi_vulnerability_scenarios: Remote File Inclusion vulnerability scenarios, focusing on PHP code injection and RCE. Technologies: PHP, Docker. GitHub stars GitHub forks

Blockchain Security

guidelines, best practices, and in-depth articles. Technologies: Markdown (Documentation). GitHub stars GitHub forks


๐Ÿ“ˆ My GitHub Stats

Your GitHub stats


๐Ÿ“ซ How to Reach Me


Feel free to fork and star my repositories if you find them useful!

backup-finder's People

Contributors

moeinfatehi avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

backup-finder's Issues

Failed to load BApp

Hello,

Having issues after compiling with gradle successfully, when trying to import the jar file as extension into Burp suite v2024.5, keep getting "The provided file is not in the required format. To install extensions that have not been downloaded from BApp store, please use the Exntesions tab"

In the BApp store, the BackupFinder is very outdated ( 2022 ).

Fallowed exact steps described multiple times.

Some assistance would be appreciated, maybe compiled jar file in the correct format?

Thank you!

Cookie Header is missing

It would be neat if backup finder sends its request along with the cookie(s) of the original request. Otherwise only unauthenticated requests are sent out and thus, the output has no meaning (in some cases).

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.