Skip to content

About

A BurpSuite extension that applys sequences of encode/decode operations before pasting clipboard text to a request editor

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

Paste Encoder — BurpSuite Extension

A Burp Suite tab that works like Decoder, but the source is your clipboard, and the chain of steps you build becomes what gets applied automatically when you hit Ctrl+Shift+E inside any HTTP message editor (Repeater, Intruder, Proxy, etc.). When text is highlighted, the Ctrl+Shift+E hotkey will replace the hightlighted text with the clipboard contents encoded/decoded through the active chain. If no text is hightlighted, the clipboard text will be encoded/decoded according to the active chain and inserted as a regular paste.

When text is highlighted, the Ctrl+Shift+K hotkey will apply the configured encode/decode chain to the hightlighted text.

Both hotkeys are configurable within the extension's tab.

Image

Project layout

paste-encode-extension/
├── pom.xml
└── src/main/java/burp/pasteencode/
    ├── PasteEncodeExtension.java   # entry point: registers tab + hotkey
    ├── ChainConfig.java            # ordered transform list, persisted across restarts
    ├── ChainTabPanel.java          # the Decoder-style UI (cascading stage panels)
    └── Transforms.java             # Transform interface + built-in transforms

Building

mvn clean package

This produces target/paste-encode-extension.jar.

Loading into Burp

Burp Suite > Extensions > Installed > Add > select the jar, extension type Java.

Once loaded you should see:

  • A new Paste-Encode tab in the main Burp window, with a clipboard preview, a stack of stage panels showing the output after each transform, and controls to add/remove/clear steps.
  • Ctrl+Shift+E and Ctrl+Shift+E available (and listed in Burp's command palette) whenever focus is inside an HTTP message editor.

Extending

  • Add more entries to BuiltInTransform in Transforms.java for things like double URL-encode, hex-encode, gzip+base64, JWT none-alg reformatting, etc.
  • ChainConfig already fires listeners on every change, so the tab UI updates live — any new UI (e.g. a "preview" pane elsewhere) can hook the same listener.
  • If you want per-target or per-project chains rather than one global chain, swap api.persistence().extensionData() (global) for api.persistence().projectData() (per-project) in ChainConfig.save/load.

About

A BurpSuite extension that applys sequences of encode/decode operations before pasting clipboard text to a request editor

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages