项目作者: GoSecure

项目描述 :
Burp和ZAP插件用于分析Content-Security-Policy标头或通过爬网来生成模板CSP配置
高级语言: Java
项目地址: git://github.com/GoSecure/csp-auditor.git
创建时间: 2016-03-16T14:36:55Z
项目社区:https://github.com/GoSecure/csp-auditor

开源协议:

下载


CSP Auditor Build Status

This plugin provides:

  • a readable view of CSP Headers in Response Tab
  • passive scan rules to detect weak CSP configuration
  • a CSP configuration generator based on the Burp crawler or using manual browsing

This project is packaged as a ZAP and Burp plugin.

Download

Last updated : August 3th 2017

Screenshots

Passive rules and custom tab:

CSP Auditor Burp Plugin

Configuration builder:

CSP Auditor Burp Plugin

Building the plugin

Type the following command:

  1. ./gradlew build

or if you have already Gradle installed on your machine:

  1. gradle build

Read more

For more context around Content-Security-Policy and how to apply it to your website see our blog posts on the topic: