You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何为Burp Suite的Jython2.7扩展集成js2py运行JavaScript?

问题:Burp Suite扩展中集成js2py到Jython的问题

背景

我正在为Burp Suite编写Python扩展,功能是解析Postman集合JSON文件,将其中的所有请求添加到Burp站点地图。目前已成功解析请求本身、请求体及请求头,但部分请求包含JavaScript编写的预请求脚本,需要处理这些脚本中的变量。

本地Python 2.7环境下的实现代码

我使用js2py库编写了如下代码来运行预请求脚本:

import js2py
class Postman:
    collectionVariables = []
    globals = []
    environment = []

    def run_pre_request_scripts(self, request):
        exec_script = self.get_exec_scripts(request)
        if exec_script is not None:
            js_code = self.reformat_script(exec_script)
            js_code = "pm = {'collectionVariables': [], 'globals': [], 'environment': []};\nvariable = {}\n" + js_code + "\npm;"

            pm = js2py.eval_js(js_code)

            self.collectionVariables.append(pm.collectionVariables)
            self.globals.append(pm.globals)
            self.environment.append(pm.environment)

    def reformat_script(self, str_list):
        formatted_script = []
        for s in str_list:
            if not s.strip():
                continue
            elif s.startswith(('var', 'const', 'let')):
                formatted_str = s.strip().replace('var', '').replace('const', '').replace('let', '').strip(" ")
                formatted_script.append(formatted_str)
            elif "pm.collectionVariables.set" in s:
                name = s.split("(")[1].split(",")[0].strip("'")
                value = s.split(",")[1].strip().strip(")")
                formatted_str = "pm.collectionVariables.push({'value': %s, 'key': '%s'});" % (value, name)
                formatted_script.append(formatted_str)
            elif "pm.globals.set" in s:
                variable_name = s.split("(")[1].split(",")[0].strip().strip('"')
                formatted_str = "pm.globals.push({'value': %s, 'key': '%s'});" % (variable_name, variable_name)
                formatted_script.append(formatted_str)
            elif "pm.environment.set" in s:
                variable_name = s.split("(")[1].split(",")[0].strip().strip('"')
                formatted_str = "pm.environment.push({'value': %s, 'key': '%s'});" % (variable_name, variable_name)
                formatted_script.append(formatted_str)
            else:
                formatted_script.append(s.strip())

        return '\n'.join(line for line in formatted_script if not line.startswith('//'))

示例预请求脚本

pm.collectionVariables.set('today-1year','2020-01-18')
pm.collectionVariables.set('today-3year','2018-01-18')
pm.collectionVariables.set('today-5year','2016-01-18')
pm.collectionVariables.set('today-10year','2011-01-18')
pm.collectionVariables.set('today+5year','2026-01-18')

// generate random number between 1 and 10000
const number = (Math.floor(Math.random()*10000)*1);

// generate 'name'as unique value for the Party1

var CustomerName1 = "MPCustomer1" + number; 
pm.globals.set("CustomerName1", CustomerName1);

console.log("CustomerName1:", CustomerName1);


console.log("CustomerName1:", CustomerName1);

这段代码在本地Python 2.7环境下运行正常,但需要在Burp Suite中使用Jython 2.7运行,因此需要将js2py库集成到Jython的jar包中,我尝试了两种方案均失败:

方案1:使用pip安装

执行以下命令:

java -jar jython-standalone-2.7.3.jar -m pip ensurepip
java -jar jython-standalone-2.7.3.jar -m pip install js2py

出现错误:

Collecting js2py
Using cached Js2Py-0.74.tar.gz (2.5 MB)
ERROR: Error [Errno 2] No such file or directory while executing command python setup.py egg_info
ERROR: Could not install packages due to an EnvironmentError: [Errno 2] No such file or directory

方案2:手动添加到jar包

执行以下命令:

jar xf jython-standalone-2.7.3.jar
cp -r  /Library/Frameworks/Python.framework/Versions/2.7/lib/python2.7/site-packages/js2py Lib/
jar cfm jython-standalone-2.7.3-modified.jar META-INF/MANIFEST.MF .

将修改后的jar包上传至Burp后,出现错误:

AttributeError: 'tablecode' object has no attribute 'co_names'

导致脚本无法启动。

请求帮助

恳请提供将js2py集成到Jython jar包的有效方案,或提供已集成该库的Jython文件。


内容的提问来源于stack exchange,提问作者Oleksandr Ovcharenko

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.30 21:39:36