Burp Suite User Forum

Create new post

Enable J2EEScan in burpsuite pro 2

WhizzMan | Last updated: Feb 06, 2019 07:41AM UTC

I am trying to enable the J2EEScan extension. According to the readme.md on github (yay for clear instructions) I am supposed to enable it in a sessions/cookies configuration page. Even though the help documentation included with burp suite pro 2 mentions this, I think it has been omitted in the actual program? How do I get to this? Is there an alternative way to enable J2EEScan in burpsuite pro 2, or is it simply not compatible and should it not be offered as an option in the BApp Store?

Liam, PortSwigger Agent | Last updated: Feb 06, 2019 01:39PM UTC

We'll take a look at this and get back to you. Additionally, it might be worth contacting the authors of the extension: - https://github.com/ilmila/J2EEScan

PortSwigger Agent | Last updated: Feb 07, 2019 03:59PM UTC

I've taken an initial look at this and believe you can enable J2EE scanner simply by installing it from the BApp Store. It installs and runs fine for me, although I haven't got a vulnerable server to test it against.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.