Burp-Dom-Scanner – Burp Suite’s Extension To Scan And Crawl Single Page Applications
It’s a Burp Suite’s extension to allow for recursive crawling and scanning of Single Page Applications.
It runs a Chromium browser to scan the webpage for DOM-based XSS.
It can also collect all the requests (XHR, fetch, websockets, etc) issued during the crawling allowing them to be forwarded to Burp’s Proxy, Repeater and Intruder.
It requires node and DOMDig.
Download
Latest release can be downloaded here
Installation
- Install node
- Install DOMDig
- Download and load the extension
- Set both the path of
node
‘s executable and the path ofdomdig.js
in the extension’s UI.
Scanning Engine
Burp DOM Scanner uses DOMDig as the crawling and scanning engine.
DOMDig
DOMDig is a DOM XSS scanner that runs inside the Chromium web browser and it can scan single page applications (SPA) recursively. Unlike other scanners, DOMDig can crawl any webapplication (including gmail) by keeping track of DOM modifications and XHR/fetch/websocket requests and it can simulate a real user interaction by firing events. During this process, XSS payloads are put into input fields and their execution is tracked in order to find injection points and the related URL modifications.
Usage and Details
Details about usage, performed checks and reported vulnerabilities, can be found at DOMDig’s page
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below
To keep up to date follow us on the below channels.