Skip to content
New Burp Suite Extensions for Exploitation and Bypass Techniques

New Burp Suite Extensions for Exploitation and Bypass Techniques

First seen 22 Sep 2026, 14:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 14:26 UTC
  • BurpMetaFinder extracts metadata from documents, aiding in information discovery.
  • BurpSuite_403Bypasser automates scans for 403 Forbidden responses, enhancing testing efficiency.
  • Both tools are proof-of-concept extensions available on GitHub for security professionals.

Two new Burp Suite extensions have been released that enhance exploitation capabilities. The BurpMetaFinder extension allows users to extract metadata from PDF and DOCX files, potentially revealing sensitive information. The BurpSuite_403Bypasser extension automates the scanning of 403 Forbidden responses, enabling attackers to bypass directory restrictions. Both tools are available on GitHub and are aimed at security professionals for testing purposes. The BurpMetaFinder requires external libraries for installation, while the 403Bypasser uses PassiveScan to automatically handle requests. These extensions represent proof-of-concept tools and are not confirmed to be actively exploited in the wild. Users are encouraged to review and improve upon the provided code. The current status of these tools is that they are publicly available for use.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-20
BurpMetaFinder extension released
This extension extracts metadata from PDF and DOCX files, requiring external libraries for installation.
Sploitus
2026-09-22
BurpSuite_403Bypasser extension released
This extension automates the scanning of 403 Forbidden responses using PassiveScan, simplifying security assessments.
Sploitus

More articles in this cluster (2)