Herm3s is a Unicode security testing extension for Burp Suite, built with the Montoya API. It adds a Unicode tab to the Repeater request editor, where selected characters can be transformed into Unicode confusables, case variants, combining sequences, Overlong UTF-8, truncation/overflow payloads, and alternative byte encodings.
Every transformation updates the current request, so the result is immediately available in Burp's native Pretty, Raw, and Hex views.
Use this extension only for security testing with explicit authorization. Overlong, truncation, UTF-16, and NUL operations may intentionally produce non-canonical, invalid, or binary request bytes.
| Category | Operations |
|---|---|
| Confusables | ASCII to fullwidth, Greek/Cyrillic lookalikes, and Punycode/Unicode IDNA conversion |
| Case | Uppercase, lowercase, title case, swap case, and approximate case folding |
| Combining Marks | Add acute, tilde, macron, strike-through, and enclosing-circle marks, or remove combining marks |
| Overlong | 2/3/4-byte Overlong UTF-8 in raw-byte and %XX forms |
| Truncation | 8-bit truncation payloads, 16-bit Unicode overflow payloads, and local truncation verification |
| Byte Encoding | UTF-8 percent encoding, UTF-16LE, UTF-16BE, and NUL insertion |
| Utilities | Code-point inspection, up to 30 transformation undo steps, and request reset |
All operations affect only the current selection. Character-level operations require a complete, valid UTF-8 selection. Raw-byte operations may deliberately generate invalid UTF-8.
- Obtain
Herm3s-1.3.2.jar. - Open Burp Suite and go to
Extensions->Installed->Add. - Set
Extension typetoJava. - Select the extension JAR and finish loading it.
- Open Repeater and select the
Unicodetab in the request editor.
Requirements:
- JDK 21 (the generated bytecode targets Java 17)
- Access to Maven Central when dependencies are downloaded for the first time
Windows:
.\gradlew.bat clean test jarLinux/macOS:
./gradlew clean test jarThe resulting extension is written to:
build/libs/Herm3s-1.3.2.jar
- Send a request to Repeater.
- Open the
Unicoderequest tab. - Select complete characters or bytes in the upper editor.
- Choose a transformation in the lower control area.
- Check the byte count and code-point details in the status area.
- Switch to Burp's native
Pretty,Raw, orHexview to inspect and send the updated request.
Use Undo transformation or Reset request if the generated result is not suitable.
The Truncation tab separates payload generation from local verification:
8-bit truncation payload: select+0100,+0200, or+FF00, then generate the payload.16-bit overflow payload: select+10000or+100000, then generate the payload.Verify 8-bit truncation/Verify 16-bit truncation: locally simulate a vulnerable numeric conversion and confirm whether the generated code point falls back to the original character.
All offsets are hexadecimal Unicode code-point offsets, not string suffixes.
For example, / is U+002F:
U+002F + 0x0100 = U+012F
U+012F & 0x00FF = U+002F -> /
If a vulnerable backend retains only the low 8 bits, U+012F becomes / again. A 16-bit overflow follows the same principle:
U+002F + 0x10000 = U+1002F
U+1002F & 0xFFFF = U+002F -> /
The available offsets cover different Unicode pages and conversion, filtering, or storage paths. A safe Unicode implementation should preserve the original value or reject an invalid conversion instead of silently truncating it.
Overlong UTF-8 represents a code point with more bytes than required. For example, the canonical UTF-8 representation of / is 2F, while its two-byte Overlong representation is C0 AF, or %C0%AF after percent encoding.
Modern UTF-8 decoders should reject Overlong sequences. These options are intended for testing legacy decoders, proxy/backend decoding inconsistencies, and multi-stage decoding chains.
- Extension entry point:
dev.herm3s.unicode.UnicodeLabExtension - Burp integration: Montoya API
2026.4 - UI: Java Swing with Burp's
RawEditor - Tests: JUnit 5
The extension does not embed another HttpRequestEditor inside its custom HttpRequestEditorProvider, which would recursively create editors. It uses Burp's RawEditor to retain native theming, fonts, search, and binary selection behavior.
src/
|-- main/java/dev/herm3s/unicode/
| |-- UnicodeLabExtension.java
| |-- UnicodeRequestEditor.java
| `-- UnicodeTransform.java
`-- test/java/dev/herm3s/unicode/
`-- UnicodeTransformTest.java