🛡️ BurpSuite MCP服务器
BurpSuite的强大模型上下文协议(MCP)服务器实现,提供对Burp核心功能的编程访问。
](https://mseep.ai/app/x3r0k-burpsuite-mcp-server)   
🚀 特性
🔄 代理工具
- 拦截和修改HTTP/HTTPS流量
- 查看和操作请求/响应
- 访问代理历史记录
- 实时请求/响应操作
# Intercept a request
curl -X POST "http://localhost:8000/proxy/intercept" \
-H "Content-Type: application/json" \
-d '{
"url": "https://example.com",
"method": "GET",
"headers": {"User-Agent": "Custom"},
"intercept": true
}'
# View proxy history
curl "http://localhost:8000/proxy/history"🔍 扫描工具
- 主动和被动扫描
- 自定义扫描配置
- 实时问题跟踪
- 扫描状态监控
# Start a new scan
curl -X POST "http://localhost:8000/scanner/start" \
-H "Content-Type: application/json" \
-d '{
"target_url": "https://example.com",
"scan_type": "active",
"scan_configurations": {
"scope": "strict",
"audit_checks": ["xss", "sqli"]
}
}'
# Check scan status
curl "http://localhost:8000/scanner/status/scan_1"
# Stop a scan
curl -X DELETE "http://localhost:8000/scanner/stop/scan_1"📝 记录仪工具
- 全面的HTTP流量记录
- 高级过滤和搜索
- 漏洞检测
- 流量分析
- 可疑模式检测
# Get filtered logs
curl "http://localhost:8000/logger/logs?filter[method]=POST&filter[status_code]=200"
# Search logs
curl "http://localhost:8000/logger/logs?search=password"
# Get vulnerability analysis
curl "http://localhost:8000/logger/vulnerabilities"
# Get comprehensive analysis
curl "http://localhost:8000/logger/analysis"
# Clear logs
curl -X DELETE "http://localhost:8000/logger/clear"
curl "http://localhost:8000/logger/vulnerabilities/severity"🎯 漏洞检测
自动检测多种类型的漏洞:
- 🔥 XSS(跨站脚本)
- 💉 SQL注入
- 🗂️ 路径遍历
- 📁 文件包含
- 🌐 服务器端请求伪造
- 📄 XXE(XML外部实体)
- 🔒 跨站点请求伪造
- 🔄 打开重定向
- ⚡ 命令注入
🛠️ 设置
- 克隆存储库
git clone https://github.com/X3r0K/BurpSuite-MCP-Server.git
cd BurpSuite-MCP-Server- 再进行
pip install -r requirements.txt- 配置环境
# Copy .env.example to .env
cp .env.example .env
# Update the values in .env
BURP_API_KEY=Your_API_KEY
BURP_API_HOST=localhost
BURP_API_PORT=1337
BURP_PROXY_HOST=127.0.0.1
BURP_PROXY_PORT=8080
MCP_SERVER_HOST=0.0.0.0
MCP_SERVER_PORT=8000- 启动服务器
python main.py服务器将于启动http://localhost:8000
📊 分析特征
流量分析
- 请求总数
- 唯一URL
- HTTP方法分发
- 状态代码分布
- 内容类型分析
- 平均响应时间
弱点分析
- 漏洞类型摘要
- 最易受攻击的端点
- 可疑模式
- 实时漏洞检测
日志筛选
- 通过HTTP方法
- 按状态代码
- 按URL模式
- 按内容类型
- 按内容长度
- 按时间范围
- 按漏洞类型
🔒 安全考虑
- 在安全的环境中运行
- 配置适当的身份验证
- 在生产环境中使用HTTPS
- 确保BurpSuite API密钥的安全
- 监控和审核访问权限
📚 API文档
有关API的详细文档,请访问:
- Swagger用户界面:http://localhost:8000/docs
- 重新记录:http://localhost:8000/redoc
光标集成
MCP服务器已配置为与Cursor IDE无缝协作。这 .cursor 目录包含所有必要的配置文件:
配置文件
settings.json:包含MCP服务器配置
- 服务器主机和端口设置 - 端点配置 - BurpSuite代理设置 - 记录器设置 - Python解释器路径
tasks.json:定义常见任务
- 启动MCP服务器 - 运行漏洞测试 - 检查漏洞
launch.json:包含调试配置
- 调试MCP服务器 - 调试漏洞测试
在游标中使用
- 在Cursor中打开项目
- MCP服务器配置将自动加载
- 通过以下方式访问功能:
- 用于运行任务的命令面板(Ctrl+Shift+P) - 调试会话的调试菜单 - 自动Python解释器配置
服务器将可在以下位置访问 http://localhost:8000 具有以下端点:
/proxy/intercept用于请求拦截/logger用于日志记录功能/logger/vulnerabilities/severity用于漏洞分析
📝 许可证
此项目根据MIT许可证获得许可-请参阅 许可证 文件以获取详细信息。

