This extension calculate a valid WS security token for every request (In Proxy, Scanner, Intruder, Repeater, Sequencer, Extender), and replace variables in theses requests by the valid token.

It follow Web Services Security (WS-Security, WSS) published by OASIS

Using Burp WS-Security

  1. This extension only change requests targeting in scope item. So you need to add the target in the scope.
  2. Go to the WSSecurity tab, fill the password field, choose if you need the nonce to be base64 encoded or not.
  3. Click "Turn WS-Security ON". Now, for every request in scope, a valid security token will be created.
  4. In your request
  5. This extension will log in the Extender UI every request after change if you need to debug.