Burp community forum

Bapp Extension Signature

Darrell | Last updated: Dec 30, 2015 03:21PM UTC

When installing a Burp extension from the Bapp Store I see a "BappSignature.sig" file is part of the install. I assume this is a Bapp Store generated digital signature of the extender package and is checked by Burpsuite when installed. But I cannot find any documentation of this feature. Is my assumption correct? Thanks

PortSwigger Agent | Last updated: Dec 30, 2015 03:34PM UTC

That is correct. Burp validates the signature of downloaded BApps before installation.

You need to Log in to post a reply. Or register here, for free.