Burp Suite User Forum

AMF

Bob | Last updated: Apr 06, 2018 11:09PM UTC

What is the current state of AMF support within Burp and Burp plugins? Searching through old support post most AMF support seems very outdated. I'm using Pro 1.7.30. I've tried Blazer. It throws a null pointer exception when doing just about anything. I tried the plugin from NetSPI (https://github.com/NetSPI/Burp-Extensions/tree/master/BurpAMFDSer/New_APIs/executables). Loading through Extender->Extensions it doesn't show up anywhere.

PortSwigger Agent | Last updated: Apr 09, 2018 03:13PM UTC

Hi Bob, Core Burp has some support for AMF - the Scanner can using string parameters as insertion points. Until now we believed Blazer worked correctly, although with it being a third-party extension we don't test it on an ongoing basis. I will have more of a look at Blazer in the coming days. The NetSPI extension has a number of issues, which is why we didn't add it to the BApp Store.

Ben, PortSwigger Agent | Last updated: Apr 09, 2018 03:16PM UTC

Hi Chris, Blazer has not been updated in our BApp Store since 2017 and, according to the information on Github, the author is now no longer actively supporting it. Are errors preventing you from using the extension at all?

Burp User | Last updated: Apr 09, 2018 11:18PM UTC

Paul -- Thank you for any assistance. I need this on an urgent project and had never run across AMF prior to this. Please let me know what you find with Blazer.

Burp User | Last updated: Jun 22, 2018 08:12AM UTC

Don't suppose you ever got anywhere Bob/Paul? I'm looking at a pretty much identical error (currently trying to hunt down an older version of burp to see if it will work with that).

Burp User | Last updated: Jun 22, 2018 08:39AM UTC

For those that find this using an older version seemed to solve it (in my case I found an old version of Pro v1.5.21). Good Luck!

Burp User | Last updated: Oct 15, 2019 04:54PM UTC

Launching burp normally wont load, place both JAR files together (Burp + Blazer) and launch from the command line "java -classpath Blazer_v0.3.2.jar:burpsuite_pro.jar bu.StartBurp". Also, it seems like the current version of Burp doesn't have proper support. (October 2019). Testing flash in 2019 isn't easy.

You need to Log in to post a reply. Or register here, for free.