Skip to main content

PortSwigger Lab Automation Tool

Project description

Burplabs

burplabs is a modular, Python-based CLI tool that automates solving labs from PortSwigger Web Security Academy.
Its like like netexec, but made for web apps.

Basically, this is a python package named 'burplabs' which is an PortSwigger's Web Security Academy labs soluction in the form of python script. Each script includes the lab's name, proxy settings, and step-by-step solution, as well as any additional notes.


It currently has 148/230 labs (excluding expert labs) and I am adding rest of the labs daily.

This not something new but this helped me to get better with Python Scripting and I adjusted many other things. I recommend to try this when you know how lab is solved and just want to solve it. Please do not use this before understanding the concepts.

Features

  • CLI interface
  • Modular architecture – each lab is a standalone Python file
  • Custom Proxy and No Proxy also support (--proxy, --no-proxy)
  • Docker-compatible
  • Easily extensible - add your own code if you want!

Installation

Option 1: Install via pip (recommended)

Windows

python -m venv burplabs-venv
.\burplabs-venv\scripts\Activate.ps1
pip install burplabs

Option 2: Git clone

git clone https://github.com/spbavarva/portswigger-labs-scripts.git
cd portswiggerlab
pip install .

(Docker will be added soon)


Usage

View Help

burplabs -h

burplabs help

List All Available Labs

burplabs --list-labs

Interactive Mode

burplabs --interactive

and then just follow the steps. You can even enter custom proxy when it prompts or if you want to use burp proxy then just open burp and hit 'Y' when it prompts for default proxy to get requests on your burp.

Or you can hit 'n' when it prompts and you don't need to open burp at all.

Interactive Mode


Adding New Labs

To add a new lab:

  1. Create a new file in burplabs/labs/name-of-the-folder, e.g. sql_lab3.py
  2. It must define a run(url, payload, proxies=None) function
  3. That’s it! The lab will be auto-detected and usable like:
portswiggerlab sql_lab3 --url ... --payload ...

Author and Support

Credit to Rana Khalil for inspiring me for this!

Built by Sneh aka mystic_mido Portfolio: snehbavarva.com If you like it, give it a ⭐ on GitHub! That will really helps a lot to motivate me and show the significance of this small project. Thank you!

License

MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

burplabs-0.3.1.tar.gz (56.2 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

burplabs-0.3.1-py3-none-any.whl (157.7 kB view details)

Uploaded Python 3

File details

Details for the file burplabs-0.3.1.tar.gz.

File metadata

  • Download URL: burplabs-0.3.1.tar.gz
  • Upload date:
  • Size: 56.2 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.1

File hashes

Hashes for burplabs-0.3.1.tar.gz
Algorithm Hash digest
SHA256 16571a27ef5657ec7919a848ec51b8a7ad243cf7322395d29e121b6b15addcac
MD5 db1ac624dc7de4611c1075908ffc81f9
BLAKE2b-256 8bb1120d8c6f9452e71dae4f5fc6067995333b942ba4b5d482c6fb43adc1172c

See more details on using hashes here.

File details

Details for the file burplabs-0.3.1-py3-none-any.whl.

File metadata

  • Download URL: burplabs-0.3.1-py3-none-any.whl
  • Upload date:
  • Size: 157.7 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.11.1

File hashes

Hashes for burplabs-0.3.1-py3-none-any.whl
Algorithm Hash digest
SHA256 89aeff300b9b54827bee4edfbac71c0101f65e53b16cf0f0b41475e6b4df950b
MD5 6f39a38f89eb69400f5b2e6ed02a1491
BLAKE2b-256 b96d297bab0f30e6e37d2bcf7818e85c8f5328abc04c95d6163a2d092e7c453e

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page