{"id":13841967,"url":"https://github.com/tmoneypenny/conspirator","last_synced_at":"2026-01-17T15:49:10.672Z","repository":{"id":43736502,"uuid":"394040889","full_name":"tmoneypenny/conspirator","owner":"tmoneypenny","description":"An enhanced collaborator-like standalone server","archived":false,"fork":false,"pushed_at":"2023-03-07T02:55:20.000Z","size":350,"stargazers_count":9,"open_issues_count":3,"forks_count":1,"subscribers_count":4,"default_branch":"main","last_synced_at":"2024-11-21T12:44:45.230Z","etag":null,"topics":["bug-bounty","burp-extensions","security-tools"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/tmoneypenny.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2021-08-08T18:32:17.000Z","updated_at":"2023-01-31T08:13:49.000Z","dependencies_parsed_at":"2024-06-19T17:36:04.554Z","dependency_job_id":"f7a8df68-9736-43fc-b462-e56ef2bdccd8","html_url":"https://github.com/tmoneypenny/conspirator","commit_stats":{"total_commits":9,"total_committers":2,"mean_commits":4.5,"dds":"0.11111111111111116","last_synced_commit":"7996521610276e3e05b26d05cb42b5f878cd6ff6"},"previous_names":[],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/tmoneypenny/conspirator","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmoneypenny%2Fconspirator","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmoneypenny%2Fconspirator/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmoneypenny%2Fconspirator/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmoneypenny%2Fconspirator/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/tmoneypenny","download_url":"https://codeload.github.com/tmoneypenny/conspirator/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/tmoneypenny%2Fconspirator/sbom","scorecard":{"id":889993,"data":{"date":"2025-08-11","repo":{"name":"github.com/tmoneypenny/conspirator","commit":"7996521610276e3e05b26d05cb42b5f878cd6ff6"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":1.5,"checks":[{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Code-Review","score":0,"reason":"Found 0/8 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Maintained","score":0,"reason":"0 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":-1,"reason":"no dependencies found","details":null,"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":0,"reason":"Project has not signed or included provenance with any releases.","details":["Warn: release artifact v0.1.0 not signed: https://api.github.com/repos/tmoneypenny/conspirator/releases/47501135","Warn: release artifact v0.1.0 does not have provenance: https://api.github.com/repos/tmoneypenny/conspirator/releases/47501135"],"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'main'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 3 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Vulnerabilities","score":0,"reason":"20 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3553 / GHSA-mh63-6h87-95cp","Warn: Project is vulnerable to: GO-2025-3607 / GHSA-rq77-p4h8-4crw","Warn: Project is vulnerable to: GO-2022-0322 / GHSA-cg3q-j54f-5p7p","Warn: Project is vulnerable to: GO-2022-0968 / GHSA-gwc9-m7rh-j2ww","Warn: Project is vulnerable to: GO-2021-0356 / GHSA-8c26-wmh5-6g9v","Warn: Project is vulnerable to: GO-2024-2961","Warn: Project is vulnerable to: GO-2023-2402 / GHSA-45x7-px36-x8w8","Warn: Project is vulnerable to: GO-2024-3321 / GHSA-v778-237x-gjrc","Warn: Project is vulnerable to: GO-2025-3487 / GHSA-hcg3-q754-cr77","Warn: Project is vulnerable to: GO-2022-0288","Warn: Project is vulnerable to: GO-2022-0969 / GHSA-69cg-p879-7622","Warn: Project is vulnerable to: GO-2022-1144 / GHSA-xrjj-mj9h-534m","Warn: Project is vulnerable to: GO-2023-1571 / GHSA-vvpx-j8f3-3w6h","Warn: Project is vulnerable to: GO-2023-1988 / GHSA-2wrh-6pvc-2jm9","Warn: Project is vulnerable to: GO-2023-2102 / GHSA-4374-p667-p6c8","Warn: Project is vulnerable to: GHSA-qppj-fm5r-hxr3","Warn: Project is vulnerable to: GO-2024-2687 / GHSA-4v7x-pqxf-cx7m","Warn: Project is vulnerable to: GO-2024-3333","Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-24T11:26:13.741Z","repository_id":43736502,"created_at":"2025-08-24T11:26:13.741Z","updated_at":"2025-08-24T11:26:13.741Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28511851,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-17T13:38:16.342Z","status":"ssl_error","status_checked_at":"2026-01-17T13:37:44.060Z","response_time":85,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bug-bounty","burp-extensions","security-tools"],"created_at":"2024-08-04T17:01:25.039Z","updated_at":"2026-01-17T15:49:10.635Z","avatar_url":"https://github.com/tmoneypenny.png","language":"Go","funding_links":[],"categories":["Go"],"sub_categories":[],"readme":"# Conspirator\n\n**Currently, this is a personal (WIP) side-project that I work on in my spare time. I'm not taking PRs or contributions at this time.**\n\u003chr\u003e\nAn extensible collaborator-like standalone server. \n\n## Features\n* [Friendly webUI](#admin)\n* [Easily add custom routes](#routes)\n* [Poll interactions from UI or Burp](#polling)\n* [Extendable](#extending)\n* [Handles multiple zones](#dns)\n\n## Getting Started\n\nDownload a release, or compile from src using `make bundle`. This will bundle the configuration, templates, and executable into a tarball ready for upload to a server.\n\n| Command | Info |\n| ---- | ---- |\n| `./conspirator help` | Shows the help menu |\n| `./conspirator config` | Generates an example configuration |\n| `./conspirator start` | Starts the server |\n\n| Start Flags | Info |\n| ----------- | ---- |\n| `./conspirator start -c \u003cpath\u003e` | Starts conspirator using config provided |\n| `./conspirator start -p` | Enable profiler on `localhost:6060` |\n\n## Admin\n\nConspirator has a built-in `/admin` endpoint that allows the server owner to add and remove custom routes,\n poll for interaction events, view documentation, and query internal metrics right from the browser. In addition to the `/admin` endpoint, the server owner can use the bearer token available in the UI to make authenticated requests to the `/api/v1` endpoint.\n\n![admin](./docs/images/admin_home.png)\n\nAPI endpoint docs are provided by Swagger and available in the UI.\n## Routes\n\nConspirator includes API endpoints that allow the server owner to add, remove, and update custom routes. Each custom route is fully configurable with `urlPath`, `methods`, `headers`, and the response `body`. Adding routes will overwrite existing routes at the same path. Removing a route will revert the endpoint to serve a random interaction event string to the client. \n\nCustom routes are always shown under the `showRoutes` endpoint.\n\n![admin](./docs/images/admin_route.png)\n\n## Polling\nThe polling server records all interactions that were captured by the server in an event queue. Records can be retrieved from the server by issuing a simple `GET` request to the polling subdomain (`pollingSubdomain`), using a websocket (such as the UI), or through Burp/Taborator's polling UI. The polling interface is restricted to IPs present in the allowlist as the polling interface does not require authentication unless using a proxy like Collaborator++. Any IP that tries to contact the polling server will get a default interaction response instead. \n\nInteraction events can be formatted according to the `pollingEncoding` parameter in the configuration. \n- `burp` will format as JSON encoding with fields that BurpSuite uses\n\nBy default, events in the queue do not expire by a TTL like in collaborator; instead, the queue has a finite size where old events are evicted if they have not been retrieved. This allows a user to fine-tune \nthe number of events stored in memory at any given time using `maxPollingEvents` parameter. \n\n#### Configuring BurpSuite Pro\nConspirator can be used as a drop-in replacement for Burp's Collaborator Server by configuring your project options -\u003e Misc -\u003e Burp Collaborator Server with the following settings:\n\n| Setting | Value |\n| ------- | ----- |\n| Use private Collaborator Server | true |\n| Server Location | `your_fqdn_here` |\n| Polling Location | polling.`your_fqdn_here` |\n| Poll over unencrypted HTTP | false |\n\n**Note**: Some health checks may fail or throw warnings while others succeed. These checks are not essential to using Conspirator with Burp.\n## Extending\n\nConspirator supports extending the server using Go plugins. Plugins are compiled into shared library files, passed in the configuration, and loaded at runtime. \n\nTo build a plugin, it is essential to implemenent the following exported methods:\n- `NewServer(wrapper.Config) wrapper.Module`\n- `Start()`\n- `Stop()`\n\nIn addition to the exported methods, the method receiver should contain a reference to `PollingManager *polling.PollingServer`, which allows the plugin to write events to the polling server.\n\n**Note:** As of v1.8, Go plugin only works on Linux.\n\n## DNS\n\nConspirator acts as an authoritative NS for each zone specified in the configuration. The DNS server will respond to most questions including:\n- A\n- AAAA\n- CNAME\n- TXT\n- MX\n- IXFR (only for recording interactions)\n- SRV\n\n#### DNS Configuration\nTroubleshooting, DNS over TLS, Route53 and other related docs can be found in the `docs/` folder at the root of the repository.\n\n## TODO\n- Implement SMTP\n- Implement NS record\n- Add GHA \n- Implement API endpoint for DNS upserts + manage zone from UI\n- Refactor `show routes` UI page","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftmoneypenny%2Fconspirator","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Ftmoneypenny%2Fconspirator","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Ftmoneypenny%2Fconspirator/lists"}