0x727/BypassPro
对Auth/Waf 自动化bypass的burpsuite插件 observed · 2026-08-28
Health v2 · maintenance only
79/100
- Activity 81
- Release rhythm 71
- Longevity 88
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 61
- age_days: 1245
- days_rel: 115
- days_push: 115
- n_releases_24m: 4
Adoption not part of the score
1317 stars · 62 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It combines automated bypass scanning with a manual WAF workbench offering obfuscation, encoding, header spoofing, and Ghost Bits techniques.
Use cases
- bypass 403 forbidden responses during pentests
- test authorization/access control bypasses automatically
- generate WAF bypass request variants
- manually craft obfuscated requests to evade WAF parsing
- test header spoofing like X-Forwarded-For for IP restriction bypass
- encode request bodies in exotic charsets to evade WAF detection
When to choose
- you are doing offensive security testing against web apps with WAFs or access controls
- you want automated 403/401 bypass attempts inside Burp Suite
- you need a manual workbench for WAF evasion payload crafting
When to avoid
- you are not doing authorized security testing
- you need a standalone scanner outside Burp Suite
- your target is not a web application
Facets
plugin · maturity active
security penetration-testing http-client security penetration-testing web-development jvm burpsuite-extension waf-bypass 403-bypass access-control-bypass authorization-bypass ghost-bits security-testing burpsuite
1 source
- readme: https://github.com/0x727/BypassPro · fetched 2026-08-28 · 509333881d35
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| 0x727/BypassPro | main | 79 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem