{"id":13845788,"url":"https://github.com/GuoKerS/Charset_encoding-Burp","last_synced_at":"2025-07-12T03:32:08.362Z","repository":{"id":170568241,"uuid":"307679425","full_name":"GuoKerS/Charset_encoding-Burp","owner":"GuoKerS","description":"利用字符集编码绕过waf的burpsuite插件","archived":false,"fork":false,"pushed_at":"2021-03-22T11:55:28.000Z","size":5,"stargazers_count":116,"open_issues_count":0,"forks_count":11,"subscribers_count":1,"default_branch":"main","last_synced_at":"2024-11-21T19:38:44.028Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/GuoKerS.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-10-27T11:34:06.000Z","updated_at":"2024-01-10T20:32:55.000Z","dependencies_parsed_at":null,"dependency_job_id":"742f6013-c498-4794-a20d-b5f6d252e638","html_url":"https://github.com/GuoKerS/Charset_encoding-Burp","commit_stats":null,"previous_names":["guokers/charset_encoding-burp"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/GuoKerS/Charset_encoding-Burp","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GuoKerS%2FCharset_encoding-Burp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GuoKerS%2FCharset_encoding-Burp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GuoKerS%2FCharset_encoding-Burp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GuoKerS%2FCharset_encoding-Burp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/GuoKerS","download_url":"https://codeload.github.com/GuoKerS/Charset_encoding-Burp/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/GuoKerS%2FCharset_encoding-Burp/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264930754,"owners_count":23684917,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:03:36.232Z","updated_at":"2025-07-12T03:32:08.346Z","avatar_url":"https://github.com/GuoKerS.png","language":"Python","funding_links":[],"categories":["Python"],"sub_categories":[],"readme":"# BurpSuite Plugin\n通过字符集编码绕过waf的burp插件\n\n因为小伙伴在实战中有这么个需求（利用字符集编码绕过waf），所以我借着他的这个需求也学习了下burp插件的编写。\n# 预览\n## ASP.NET+IIS\n![enter description here](https://photo.o0o0.club/Charset_encoding_converter__Burp插件/wafg01.gif)\n\n# 使用说明\n其实这种方法很早就出来了，但并不通用，感觉也有IIS+ASP.NET的时候可以试一试。\n测试环境：Windows10\nBurp版本：1.7.36\nJython版本：Jython-standalone-2.7.0\n\n1. burp加载Python运行环境（Python）\n![enter description here](https://photo.o0o0.club/Charset_encoding_converter__Burp插件/1616412431734.png)\n\n2. 加载此插件\n![enter description here](https://photo.o0o0.club/Charset_encoding_converter__Burp插件/1616412464696.png)\n\n3. 在burp proxy或repeater等选项卡 中右键开启相关选项\n![enter description here](https://photo.o0o0.club/Charset_encoding_converter__Burp插件/1616412589499.png)\n\n![enter description here](https://photo.o0o0.club/Charset_encoding_converter__Burp插件/1616412639010.png)\n\n不通用\nNginx+php\t No\u003c/br\u003e\nApache+php\t No\u003c/br\u003e\nIIS+ASP.NET勉强能用\n\n中文无解（比如上传场景）。。。\n\n# 支持列表如下\nTarget |Post\u003c/br\u003e(application/x-www-form-urlencoded)|Note(s)\n-|:-:|:-:\nNginx,uWSGI-Django-Python3 | IBM037, IBM500, cp875, IBM1026, IBM273|[x] query string and body were encoded\u003c/br\u003e[x] url-decoded parameters in query string and body afterwards\u003c/br\u003e[x] equal sign and ampersand needed to be encoded as well (no url-encoding\nNginx,uWSGI-Django-Python2|IBM037, IBM500, cp875, IBM1026, utf-16, utf-32, utf-32BE, IBM424|[x] query string and body were encoded\u003c/br\u003e[x] url-encoded parameters in query string and body\u003c/br\u003e[x] equal sign and ampersand should not be encoded in any way\nApache-TOMCAT8-JVM1.8-JSP|IBM037, IBM500, IBM870, cp875, IBM1026, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM290, IBM297, IBM420, IBM424, IBM-Thai, IBM871, cp1025|[x] query string in its original format (not encoded – could be url- encoded as usual)\u003c/br\u003e[x] equal sign and ampersand should not be encoded in any way\u003c/br\u003e[x] body could be sent with/without url-encoding\nApache-TOMCAT7-JVM1.6-JSP|IBM037, IBM500, IBM870, cp875, IBM1026, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM297, IBM420, IBM424, IBM-Thai, IBM871, cp1025|[x] query string in its original format (not encoded)\u003c/br\u003e[x] equal sign and ampersand should not be encoded\u003c/br\u003e[x] body could be sent with/without url-encoding\nApache -PHP5(mod_php \u0026 FastCGI)|None|N/A\nIIS8-PHP7.1-FastCGI|None|N/A\nIIS6, 7.5, 8, 10 -ASP Classic|None|N/A\nIIS6, 7.5, 8, 10 -ASPX (v4.x)|IBM037, IBM500, IBM870, cp875, IBM1026, IBM01047, IBM01140, IBM01141, IBM01142, IBM01143, IBM01144, IBM01145, IBM01146, IBM01147, IBM01148, IBM01149, utf-16, unicodeFFFE, utf-32, utf-32BE, IBM273, IBM277, IBM278, IBM280, IBM284, IBM285, IBM290, IBM297, IBM420,IBM423, IBM424, x-EBCDIC-KoreanExtended, IBM-Thai, IBM871, IBM880, IBM905, IBM00924, cp1025|[x] query string and body were encoded\u003c/br\u003e[x] equal sign and ampersand should not be encoded\u003c/br\u003e[x] body could be sent with/without url-encoding\n\n# 参考资料\nhttps://www.nccgroup.com/uk/about-us/newsroom-and-events/blogs/2017/august/request-encoding-to-bypass-web-application-firewalls/\n\n# 食用说明\n开袋不即食，需要蘸着jython吃","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FGuoKerS%2FCharset_encoding-Burp","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FGuoKerS%2FCharset_encoding-Burp","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FGuoKerS%2FCharset_encoding-Burp/lists"}