Skip to content
DReazerPublic

About

A Burp Suite extension for conducting security testing on Unicode normalization.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

5 Commits

Folders and files

Repository files navigation

Herm3s

Herm3s is a Unicode security testing extension for Burp Suite, built with the Montoya API. It adds a Unicode tab to the Repeater request editor, where selected characters can be transformed into Unicode confusables, case variants, combining sequences, Overlong UTF-8, truncation/overflow payloads, and alternative byte encodings.

Every transformation updates the current request, so the result is immediately available in Burp's native Pretty, Raw, and Hex views.

Use this extension only for security testing with explicit authorization. Overlong, truncation, UTF-16, and NUL operations may intentionally produce non-canonical, invalid, or binary request bytes.

Features

Category Operations
Confusables ASCII to fullwidth, Greek/Cyrillic lookalikes, and Punycode/Unicode IDNA conversion
Case Uppercase, lowercase, title case, swap case, and approximate case folding
Combining Marks Add acute, tilde, macron, strike-through, and enclosing-circle marks, or remove combining marks
Overlong 2/3/4-byte Overlong UTF-8 in raw-byte and %XX forms
Truncation 8-bit truncation payloads, 16-bit Unicode overflow payloads, and local truncation verification
Byte Encoding UTF-8 percent encoding, UTF-16LE, UTF-16BE, and NUL insertion
Utilities Code-point inspection, up to 30 transformation undo steps, and request reset

All operations affect only the current selection. Character-level operations require a complete, valid UTF-8 selection. Raw-byte operations may deliberately generate invalid UTF-8.

Installation

Install a built JAR

  1. Obtain Herm3s-1.3.2.jar.
  2. Open Burp Suite and go to Extensions -> Installed -> Add.
  3. Set Extension type to Java.
  4. Select the extension JAR and finish loading it.
  5. Open Repeater and select the Unicode tab in the request editor.

Build from source

Requirements:

  • JDK 21 (the generated bytecode targets Java 17)
  • Access to Maven Central when dependencies are downloaded for the first time

Windows:

.\gradlew.bat clean test jar

Linux/macOS:

./gradlew clean test jar

The resulting extension is written to:

build/libs/Herm3s-1.3.2.jar

Usage

  1. Send a request to Repeater.
  2. Open the Unicode request tab.
  3. Select complete characters or bytes in the upper editor.
  4. Choose a transformation in the lower control area.
  5. Check the byte count and code-point details in the status area.
  6. Switch to Burp's native Pretty, Raw, or Hex view to inspect and send the updated request.

Use Undo transformation or Reset request if the generated result is not suitable.

Truncation

The Truncation tab separates payload generation from local verification:

  • 8-bit truncation payload: select +0100, +0200, or +FF00, then generate the payload.
  • 16-bit overflow payload: select +10000 or +100000, then generate the payload.
  • Verify 8-bit truncation / Verify 16-bit truncation: locally simulate a vulnerable numeric conversion and confirm whether the generated code point falls back to the original character.

All offsets are hexadecimal Unicode code-point offsets, not string suffixes.

For example, / is U+002F:

U+002F + 0x0100 = U+012F
U+012F & 0x00FF = U+002F  ->  /

If a vulnerable backend retains only the low 8 bits, U+012F becomes / again. A 16-bit overflow follows the same principle:

U+002F + 0x10000 = U+1002F
U+1002F & 0xFFFF = U+002F  ->  /

The available offsets cover different Unicode pages and conversion, filtering, or storage paths. A safe Unicode implementation should preserve the original value or reject an invalid conversion instead of silently truncating it.

Overlong UTF-8

Overlong UTF-8 represents a code point with more bytes than required. For example, the canonical UTF-8 representation of / is 2F, while its two-byte Overlong representation is C0 AF, or %C0%AF after percent encoding.

Modern UTF-8 decoders should reject Overlong sequences. These options are intended for testing legacy decoders, proxy/backend decoding inconsistencies, and multi-stage decoding chains.

Implementation

  • Extension entry point: dev.herm3s.unicode.UnicodeLabExtension
  • Burp integration: Montoya API 2026.4
  • UI: Java Swing with Burp's RawEditor
  • Tests: JUnit 5

The extension does not embed another HttpRequestEditor inside its custom HttpRequestEditorProvider, which would recursively create editors. It uses Burp's RawEditor to retain native theming, fonts, search, and binary selection behavior.

Project Structure

src/
|-- main/java/dev/herm3s/unicode/
|   |-- UnicodeLabExtension.java
|   |-- UnicodeRequestEditor.java
|   `-- UnicodeTransform.java
`-- test/java/dev/herm3s/unicode/
    `-- UnicodeTransformTest.java

References

About

A Burp Suite extension for conducting security testing on Unicode normalization.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages