Configure Jython environment

First go to Jython official website to download the installation files

Just click the next step in the installation process, but remember the installation location:

Open the extension of burp after successful installation:

Select jython.jar under the installation path just remembered

Load the extension we just wrote.

Use of extensions

To view the proxy history:

If there is ID information in the returned packet, it will be marked in red

If the returned packet contains mobile number information, it will be marked in blue

If the returned packet contains GPS position information, it will be marked in green

In the output window of the burp extension, the sensitive information matched will be output in detail for future query.

The function of JSON decoder is an open source function on GitHub, but it does not support modifying the parsed data, so I modified it and added it to my program,


