Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Ghost-Js-Burp-Extension: Burp Suite Extension to Detect Hardcoded Secrets & Endpoints in JavaScript

Summary

A Burp Suite extension using the Montoya API that passively analyzes JS, HTML, and JSON responses for 150+ secret types (cloud credentials, API keys, tokens, private keys) and maps hidden API endpoints. It features active script bundle fetching, background scanning, and false-positive filtering.

Why it matters

Streamlines JavaScript reconnaissance during bug bounty hunting and web penetration testing by uncovering hidden attack surfaces and exposed secrets with minimal noise.
Published
Collected

original ↗

Related coverage

back