/ntlm-challenge-decoder

Burp extension to decode NTLM SSP headers and extract domain/host information

Primary LanguageKotlin

burp-ssp-decoder

Burp SSP Decoder

Burp extension to decode NTLM SSP headers. NTLM challenges over HTTP allows us to decode interesting information about a server, such as:

  • The server's hostname
  • The server's operating system
  • The server's timestamp
  • The domain's name
  • The domain's FQDN
  • The parent domain's name

Build the plugin

$ gradle build

The compiled plugin is located at build/libs/burp-ssp-decoder.jar

Sources, credits