The `ci` task will +still generate a minimal `pom.xml` as part of the `uber` task, unless you remove `version` +from `build.clj`. + +Start Burp with `clojure.jar` imported so it can be used with our uberjar: +``` +$ java -cp clojure.jar -jar -Xmx8g burpsuite_pro_v2023.2.3.jar +``` + +After loading the extension from the `target` directory in Burp, it +will start a REPL on port 6969 that can be accessed from any REPL +client (such as Emacs + Cider). + + +# Special thanks + + for laying the groundwork. diff --git a/build.clj b/build.clj new file mode 100644 index 0000000..11e2714 --- /dev/null +++ b/build.clj @@ -0,0 +1,47 @@ +(ns build + (:refer-clojure :exclude [test]) + (:require [ :as b])) + +(def lib 'net.clojars.subgraph/burp-clj-montoya) +(def version "0.1.0-SNAPSHOT") +(def main 'burp-clj-montoya.burp-clj-montoya) +(def class-dir "target/classes") + +(defn test "Run all the tests." [opts] + (let [basis (b/create-basis {:aliases [:test]}) + cmds (b/java-command + {:basis basis + :main 'clojure.main + :main-args ["-m" "cognitect.test-runner"]}) + {:keys [exit]} (b/process cmds)] + (when-not (zero? exit) (throw (ex-info "Tests failed" {})))) + opts) + +(defn- uber-opts [opts] + (assoc opts + :lib lib :main main + :uber-file (format "target/%s-%s.jar" lib version) + :basis (b/create-basis {}) + :class-dir class-dir + :src-dirs ["src"] + :ns-compile [main])) + +(defn compile-java [_] + (b/javac {:src-dirs ["java"] + :class-dir class-dir + :basis (b/create-basis {:project "deps.edn"})})) + ;;:javac-opts ["-source" "8" "-target" "8"]})) + +(defn ci "Run the CI pipeline of tests (and build the uberjar)." [opts] + (test opts) + (b/delete {:path "target"}) + (compile-java nil) + (let [opts (uber-opts opts)] + (println "\nCopying source...") + (b/copy-dir {:src-dirs ["resources" "src"] :target-dir class-dir}) + (println (str "\nCompiling " main "...")) + (b/compile-clj opts) + (println "\nBuilding JAR...") + (b/uber opts)) + opts) + diff --git a/deps.edn b/deps.edn new file mode 100644 index 0000000..2aed7fa --- /dev/null +++ b/deps.edn @@ -0,0 +1,19 @@ +{:paths ["src" "resources"] + :deps {org.clojure/clojure {:mvn/version "1.11.1"} + net.portswigger.burp.extensions/montoya-api {:mvn/version "2023.3"} + nrepl/nrepl {:mvn/version "1.0.0"} + cider/cider-nrepl {:mvn/version "0.30.0"} + com.taoensso/timbre {:mvn/version "6.1.0"}} + :aliases + {:run-m {:main-opts ["-m" "burp-clj-montoya"]} + :run-x {:ns-default burp-clj-montoya + :exec-fn greet + :exec-args {:name "Clojure"}} + :build {:deps {io.github.clojure/ + {:git/tag "v0.9.2" :git/sha "fe6b140"} + net.portswigger.burp.extensions/montoya-api {:mvn/version "2023.3"}} + :ns-default build} + :test {:extra-paths ["test"] + :extra-deps {org.clojure/test.check {:mvn/version "1.1.1"} + io.github.cognitect-labs/test-runner + {:git/tag "v0.5.1" :git/sha "dfb30dd"}}}}} diff --git a/doc/ b/doc/ new file mode 100644 index 0000000..7b1c089 --- /dev/null +++ b/doc/ @@ -0,0 +1,3 @@ +# Introduction to burp-clj-montoya + +TODO: write [great documentation]( diff --git a/java/burp/ b/java/burp/ new file mode 100644 index 0000000..caf568d --- /dev/null +++ b/java/burp/ @@ -0,0 +1,28 @@ +package burp_clj_montoya; + +import; +import clojure.lang.IFn; + +import burp.api.montoya.BurpExtension; +import burp.api.montoya.MontoyaApi; +import burp.api.montoya.logging.Logging; + +public class BurpExtender implements BurpExtension +{ + @Override + public void initialize(MontoyaApi api) + { + + Thread.currentThread().setContextClassLoader(this.getClass().getClassLoader()); + IFn require = Clojure.var("clojure.core", "require"); + + // API hook is stored globally in a state atom for later use + require.invoke("burp-clj-montoya.extender")); + IFn set_api = Clojure.var("burp-clj-montoya.extender", "set!"); + set_api.invoke(api); + + require.invoke("burp-clj-montoya.core")); + IFn register = Clojure.var("burp-clj-montoya.core", "register"); + register.invoke(api); + } +} diff --git a/resources/.keep b/resources/.keep new file mode 100644 index 0000000..e69de29 diff --git a/src/burp_clj_montoya/burp_clj_montoya.clj b/src/burp_clj_montoya/burp_clj_montoya.clj new file mode 100644 index 0000000..026648c --- /dev/null +++ b/src/burp_clj_montoya/burp_clj_montoya.clj @@ -0,0 +1,12 @@ +(ns burp-clj-montoya.burp-clj-montoya + (:gen-class)) + +(defn greet + "Callable entry point to the application." + [data] + (println (str "Hello, " (or (:name data) "World") "!"))) + +(defn -main + "I don't do a whole lot ... yet." + [& args] + (greet {:name (first args)})) diff --git a/src/burp_clj_montoya/burp_extender.clj b/src/burp_clj_montoya/burp_extender.clj new file mode 100644 index 0000000..c16d68a --- /dev/null +++ b/src/burp_clj_montoya/burp_extender.clj @@ -0,0 +1,4 @@ +(ns burp-clj-montoya.burp-extender + (:require [burp-clj-montoya.state :as state]) + + diff --git a/src/burp_clj_montoya/core.clj b/src/burp_clj_montoya/core.clj new file mode 100644 index 0000000..92b87a3 --- /dev/null +++ b/src/burp_clj_montoya/core.clj @@ -0,0 +1,10 @@ +(ns burp-clj-montoya.core + (:require [burp-clj-montoya.nrepl :as nrepl])) + +(defn register [api] + (let [logging (-> api (.logging)) + extension (-> api (.extension))] + (.setName extension "Clojure Montoya Plugin") + (nrepl/stop-nrepl) + (nrepl/start-nrepl logging))) + diff --git a/src/burp_clj_montoya/extender.clj b/src/burp_clj_montoya/extender.clj new file mode 100644 index 0000000..151a1a9 --- /dev/null +++ b/src/burp_clj_montoya/extender.clj @@ -0,0 +1,87 @@ +(ns burp-clj-montoya.extender + (:require [burp-clj-montoya.state :as state]) + (:refer-clojure :exclude [get])) + +(defn set! + [callbacks] + (swap! state/state assoc :extender callbacks)) + +(defn get [] + (:extender @state/state)) + +(defn- add-callback! + "Add callback registration + `class-k` category key + `cb-k` callback key + `cb-obj` callback object" + [class-k cb-k cb-obj] + (swap! state/state update class-k assoc cb-k cb-obj)) + +(defn- remove-callback! + [class-k cb-k] + (swap! state/state update class-k dissoc cb-k)) + +(defn get-callback-obj + "Get callback object" + [class-k cb-k] + (get-in @state/state [class-k cb-k])) + +(defn get-callbacks + "Get callbacks" + [class-k] + (get @state/state class-k)) + +;; (defmacro defcallback +;; [callback get-cb-method-name] +;; (let [cb-name (name callback) +;; cb-key (csk/->kebab-case-keyword callback) +;; register-method (-> (str "register" callback) +;; csk/->camelCaseSymbol) +;; register-name-s (str "register" cb-name "!") +;; register-name (csk/->kebab-case-symbol register-name-s) +;; registered? (-> (str cb-name "-registered?") +;; csk/->kebab-case-symbol) +;; remove-method (-> (str "remove" cb-name) +;; csk/->camelCaseSymbol) +;; remove-name-s (str "remove" cb-name "!") +;; remove-name (csk/->kebab-case-symbol remove-name-s) +;; get-by-key (-> (str "get" cb-name "ByKey") +;; csk/->kebab-case-symbol) +;; get-all-method get-cb-method-name +;; get-all-name (-> (str "get-all-" cb-name) +;; csk/->kebab-case-symbol) +;; remove-all-name (-> (str "remove-all-" cb-name "!") +;; csk/->kebab-case-symbol)] +;; `(do +;; (defn ~registered? [k#] +;; (-> (get-callback-obj ~cb-key k#) +;; boolean)) + +;; (defn ~register-name [k# cb#] +;; (if (~registered? k#) +;; (log/warn ~register-name-s "already registered:" k#) +;; (do +;; ;;(log/info ~register-name-s k#) +;; (. (:extender @state/state) ~register-method cb#) +;; (add-callback! ~cb-key k# cb#)))) + +;; (defn ~remove-name [k#] +;; (if-let [cb# (get-callback-obj ~cb-key k#)] +;; (do +;; (log/info ~remove-name-s k#) +;; (. (:extender @state/state) ~remove-method cb#) +;; (remove-callback! ~cb-key k#)) +;; ;;(log/warn ~remove-name-s "not found:" k#) +;; )) + +;; (defn ~get-by-key [k#] +;; (get-callback-obj ~cb-key k#)) + +;; (defn ~get-all-name [] +;; (. (:extender @state/state) ~get-all-method)) + +;; (defn ~remove-all-name [] +;; ;;(log/info ~remove-all-name) +;; (doseq [[k# obj#] (get-callbacks ~cb-key)] +;; (. (:extender @state/state) ~remove-method obj#) +;; (remove-callback! ~cb-key k#)))))) diff --git a/src/burp_clj_montoya/nrepl.clj b/src/burp_clj_montoya/nrepl.clj new file mode 100644 index 0000000..bac398c --- /dev/null +++ b/src/burp_clj_montoya/nrepl.clj @@ -0,0 +1,65 @@ +(ns burp-clj-montoya.nrepl + (:require [burp-clj-montoya.state :as state] + [cider.nrepl] + [nrepl.server :as server] + [taoensso.timbre :as log]) + (:import [clojure.lang DynamicClassLoader RT])) + +(defmacro with-exception-default + [value & body] + `(try ~@body + (catch Exception e# + (do (log/error e#) + ~value)))) + +(defmacro dyn-call + [ns-sym] + (let [ns (-> (namespace ns-sym) + symbol) + sym (-> (name ns-sym) + symbol)] + `(do + (require '~ns) + (ns-resolve '~ns '~sym)))) + +(def base-class-loader (DynamicClassLoader. (.getClassLoader clojure.lang.Compiler))) +(defn ensure-dynamic-classloader + "Ensure class can be dynamically loaded" + [] + (let [thread (Thread/currentThread) + context-class-loader (.getContextClassLoader thread)] + (when-not (instance? DynamicClassLoader context-class-loader) + (prn "set new dynamic classloader for thread:" (.getName thread)) + (.setContextClassLoader thread base-class-loader)))) + +(defn wrap-classloader + [h] + (fn [msg] + (ensure-dynamic-classloader) + (h msg))) + +(defn started? + [] + (-> (:nrepl-server @state/state) + boolean)) + +(defn stop-nrepl + [] + (when-let [server (:nrepl-server @state/state)] + ((dyn-call nrepl.server/stop-server) server) + (swap! state/state dissoc :nrepl-server))) + +(defn start-nrepl [logging] + (when-not (started?) + (.logToOutput logging "Attempting to start nrepl") + (let [cider-nrepl-handler (dyn-call cider.nrepl/cider-nrepl-handler) + start-server (dyn-call nrepl.server/start-server) + nrepl-server (start-server + :bind "" + :port 6969 + :handler (-> cider-nrepl-handler + wrap-classloader))] + (swap! state/state assoc :nrepl-server nrepl-server) + (.logToOutput logging "nrepl started.")))) + + diff --git a/src/burp_clj_montoya/proxy.clj b/src/burp_clj_montoya/proxy.clj new file mode 100644 index 0000000..317ffca --- /dev/null +++ b/src/burp_clj_montoya/proxy.clj @@ -0,0 +1,31 @@ +(ns burp-clj-montoya.proxy + (:require [burp-clj-montoya.extender :as extender]) + (:import java.util.ArrayList + burp.api.montoya.proxy.ProxyHttpRequestResponse)) + +(defn disable-intercept + [] + (-> (extender/get) + (.proxy) + (.disableIntercept))) + +(defn enable-intercept + [] + (-> (extender/get) + (.proxy) + (.enableIntercept))) + +(defn history + [] + (-> (extender/get) + (.proxy) + (.history) + (into []))) + +(defn web-socket-history + [] + (-> (extender/get) + (.proxy) + (.webSockethistory))) + + diff --git a/src/burp_clj_montoya/repeater.clj b/src/burp_clj_montoya/repeater.clj new file mode 100644 index 0000000..6d316cf --- /dev/null +++ b/src/burp_clj_montoya/repeater.clj @@ -0,0 +1,15 @@ +(ns burp-clj-montoya.repeater + (:require [burp-clj-montoya.extender :as extender])) + +(defn send-to-repeater + [request] + (-> (extender/get) + (.repeater) + (.sendToRepeater request))) + +(defn send-to-repeater + [request name] + (-> (extender/get) + (.repeater) + (.sendToRepeater request name))) + diff --git a/src/burp_clj_montoya/scope.clj b/src/burp_clj_montoya/scope.clj new file mode 100644 index 0000000..9d2dddd --- /dev/null +++ b/src/burp_clj_montoya/scope.clj @@ -0,0 +1,24 @@ +(ns burp-clj-montoya.scope + (:require [burp-clj-montoya.extender :as extender])) + + +(defn is-in-scope? + [url] + (-> (extender/get) + (.scope) + (.isInScope url))) + +(defn include-in-scope + [url] + (-> (extender/get) + (.scope) + (.includeInScope url))) + +(defn exclude-from-scope + [url] + (-> (extender/get) + (.scope) + (.includeInScope url))) + + + diff --git a/src/burp_clj_montoya/sitemap.clj b/src/burp_clj_montoya/sitemap.clj new file mode 100644 index 0000000..b71d963 --- /dev/null +++ b/src/burp_clj_montoya/sitemap.clj @@ -0,0 +1,28 @@ +(ns burp-clj-montoya.sitemap + (:require [burp-clj-montoya.extender :as extender]) + (:import burp.api.montoya.sitemap.SiteMapFilter + burp.api.montoya.http.message.HttpRequestResponse)) + +(defn site-map-filter + [prefix] + (SiteMapFilter/prefixFilter prefix)) + +(defn issues + ([] (-> (extender/get) + (.siteMap) + (.issues))) + ([prefix] (-> (extender/get) + (.siteMap) + (.issues (site-map-filter prefix))))) + +(defn request-responses + [] + (-> (extender/get) + (.siteMap) + (.requestResponses))) + +(defn request-responses + [prefix] + (-> (extender/get) + (.siteMap) + (.requestResponses (site-map-filter prefix)))) diff --git a/src/burp_clj_montoya/state.clj b/src/burp_clj_montoya/state.clj new file mode 100644 index 0000000..f3b33a4 --- /dev/null +++ b/src/burp_clj_montoya/state.clj @@ -0,0 +1,3 @@ +(ns burp-clj-montoya.state) + +(def state (atom nil)) diff --git a/test/burp_clj_montoya/burp_clj_montoya_test.clj b/test/burp_clj_montoya/burp_clj_montoya_test.clj new file mode 100644 index 0000000..c8bef4f --- /dev/null +++ b/test/burp_clj_montoya/burp_clj_montoya_test.clj @@ -0,0 +1,7 @@ +(ns burp-clj-montoya.burp-clj-montoya-test + (:require [clojure.test :refer :all] + [burp-clj-montoya.burp-clj-montoya :refer :all])) + +(deftest a-test + (testing "FIXME, I fail." + (is (= 1 1))))