Tuesday, October 6, 2026

ActiveScanPlusPlus for extending Burp Suites active scan coverage

ActiveScanPlusPlus for extending Burp Suite's active scan coverage

ActiveScanPlusPlus is a Burp Suite extension that augments active and passive scanning with checks for host header attacks, template injection, XXE, and legacy RCE CVEs during authorized web application assessments.

Toolalbinowax/ActiveScanPlusPlus — Burp Suite extension that extends active and passive scanning with low network overhead
CategoryBurp Suite scanning extension (Java)
Primary UseEnhancing Burp Scanner active scans during authorized penetration tests to surface host header attacks, input transformation anomalies, and code injection classes
Safe UseFor use exclusively in authorized penetration tests, bug bounty programs on in-scope assets, and internal lab environments with written permission
Telemetry NoteThe extension's probes generate distinctive fuzzed requests in Burp's proxy history and target logs; blue teams will see repeated anomalous payloads and error-triggering traffic in WAF/SIEM telemetry

ActiveScanPlusPlus is a Burp Suite extension written by James Kettle (albinowax) that extends the platform's built-in active and passive scanning with a set of checks aimed at what the README calls "advanced testers." What makes it notable is the design philosophy stated up front: it is built to add minimal network overhead while surfacing application behaviour that stock Burp Scanner does not flag. The repo sits at roughly 667 stars, is licensed under Apache-2.0, and as of the 2.0.0 release is a pure Java codebase — a significant architectural shift, since earlier versions ran on Jython, a constraint the changelog winks at with its note about people "foolishly" trying Jython 2.7 beta.

The capability list in the README reads like a curated history of web exploitation research, which makes sense given the author's role at PortSwigger. The extension looks for potential host header attack surface — password reset poisoning, cache poisoning, and DNS rebinding — plus Edge Side Includes handling, XML input handling, and what it calls "suspicious input transformation." That last category is the most conceptually interesting: instead of pattern-matching known payloads, it sends expressions like 7*7 and checks whether the response echoes back 49, or whether input escaping like \\ comes back transformed to \. This is behavioural detection, catching sinks the tester didn't know existed rather than confirming vulncerabilities already catalogued.

That input-transformation logic feeds directly into the code injection checks. The extension detects blind code injection via expression language, Ruby's open() and Perl's open() — two function-level quirks where a filename argument can be abused into shell command execution. A Razor template injection check using @(7*7) was added back in 1.0.19 and follows the same arithmetic-probe pattern. The elegance is that a single feedback signal — did the application evaluate our expression? — covers multiple server-side technologies without hand-crafting per-framework payloads.

The second major bucket is CVE-specific detection, and the changelog traces a decade of high-impact server-side bugs. The extension added checks for CVE-2014-6271 and CVE-2014-6278 (shellshock) within days of disclosure in 2014, then accumulated tests for CVE-2015-2080 (Jetty), CVE-2017-5638 (Struts S2-045), CVE-2017-12629 (Solr/Lucene via XXE), CVE-2018-11776 (Struts namespace RCE), CVE-2019-5418 (Rails file disclosure), CVE-2021-44228 (Log4Shell), and a Devise check tied to the author's own research on state machine bugs. For an authorized assessor encountering legacy stacks, this is essentially a bundled regression suite for the RCE classes that still bite organizations running aged infrastructure.

Host header attack coverage is where the extension shows its maturity. Version 1.0.4 explicitly reduced host header poisoning false negatives and prevented relative path overwriting (RPO) false positives by validating the page's DOCTYPE. Version 1.0.5 improved cache poisoning detection and — a detail that reveals careful operational thinking — added a cachebust parameter to prevent the scanner itself from accidentally poisoning a shared cache mid-engagement. That is the kind of side-effect awareness you want in a tool that runs against live, authorized targets: scanning infrastructure that sits in front of a CDN is genuinely risky if the scanner is careless about what it caches.

The passive side is equally considered. 1.0.12 triggers a fresh passive scan whenever an alternative code path is identified during fuzzing — meaning the passive engine re-evaluates responses that active probes caused the application to expose. The README explicitly recommends pairing it with the separate Error Message Checks extension for maximum effectiveness, a combination that surfaces issues which only manifest mid-fuzz. There is also interesting-file discovery: /.git/config and /server-status, added in 1.0.17, with the README noting the checks are easy to extend with your own patterns.

Installation is the standard Burp BApp flow: via the BApp Store, or manually through Extensions -> Installed -> Add, selecting build/libs/active-scan-plus-plus-all.jar. It requires Burp Suite Professional or Enterprise on the latest stable version — the extension APIs it depends on are not available in Community Edition, which matters for anyone planning lab work. Usage requires no special invocation: once loaded, the checks run automatically whenever you execute a normal active scan against an in-scope target.

The 2.0.0 rewrite in Java (December 2024) and the 2.0.3 release (January 2025) addressing Unicode processing issues show the project is still maintained. That Unicode work ties into the author's published research on bypassing character blocklists with Unicode overflows, illustrating how the extension serves as a vehicle for turning research findings into deployable detection logic — often within weeks of publication, as the shellshock timeline demonstrates.

For defenders, understanding what this tool does is valuable even if you never run it. Its probes — arithmetic expressions like 7*7, @(7*7), \x41, crafted Host headers, and requests converted to XML for XXE testing (1.0.18 added automatic XML conversion of existing requests) — produce recognizable traffic patterns in WAF and SIEM telemetry. Any active scan from this extension against your infrastructure outside an authorized window is a signal worth investigating; conversely, seeing its distinctive issue reports in a pentest deliverable tells you the assessor checked input-transformation sinks thoroughly.

Within an authorized workflow, ActiveScanPlusPlus occupies the slot between automated scanning and manual exploitation: it finds behaviour, not exploits. The README's framing — identifying "application behaviour that may be of interest to advanced testers" rather than claiming confirmed vulnerabilities — is honest about the tool's epistemics. Time-delay checks have historically produced false positives, and the changelog repeatedly notes false-positive reductions (1.0.13, 2.0.1). Professional use means triaging its findings manually, in an engagement with a defined scope and rules of engagement, which is exactly the context this extension was built for.

Official project repository for albinowax/ActiveScanPlusPlus.
Download Tool

Educational analysis for authorized security professionals. Use only in controlled, authorized environments.

Share articleFacebookXLinkedIn

Continue exploring

Browse all articles →

0 comentários:

Post a Comment

Note: Only a member of this blog may post a comment.