Slide 1

Slide 1 text

6 Burp extension for Cloud Security Use burp for More Vulnerability Which make Your Testing phase More Easy . 6 burp extesnsion You must need while your doing testing against cloud based application

Slide 2

Slide 2 text

Extension 1 AWS Security Checks https://github.com/PortSwigger/a ws-security-checks This extensions provides additional Scanner checks for AWS security issues.

Slide 3

Slide 3 text

Extension 2 AWS Extender https://github.com/VirtueSecurity /aws-extender This Burp Suite extension can identify and test S3 buckets as well as Google Storage buckets and Azure Storage containers for common misconfiguration issues using the boto/boto3 SDK library.

Slide 4

Slide 4 text

Extension 3 AWS Signer https://github.com/NetSPI/AWSSi gner The extension will look for the "X-AMZ-Date" header in all requests being sent by Burp. If it finds a request, it will update the signature in the request. Your request must also have an Authorization header, which should be on all AWS signed requests.

Slide 5

Slide 5 text

Extension 4 cloud_enum https://github.com/initstring/clou d_enum Enumerate public resources in AWS, Azure, and Google Cloud.

Slide 6

Slide 6 text

Extension 5 AWS Security Checks https://github.com/anvilventures/ aws-sigv4 This is a Burp extension for signing AWS requests with SigV4. Signature Version 4 is a process to add authentication information to AWS HTTP requests.

Slide 7

Slide 7 text

Extension 6 Burp-AnonymousCloud https://github.com/codewatchorg /Burp-AnonymousCloud Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities. This Help to find AWS S3 bucket URLs, Azure Storage container URLs, Google Storage container URLs, More Above

Slide 8

Slide 8 text

cyber UF Learn Cyber Security we Do Penentration Testing Choose Your Best Online Training We Help to Secure Your Network Infrastructure Ask Your Questions? Insta: @cyber_unfold Medium:https://cyberunfold.medium.com