Professional Community

IP Rotate

Note: Where applicable, usage of this extension should comply with Amazon's Customer Service Policy for Penetration Testing.

This extension automatically rotates IP addresses by routing traffic through AWS API Gateway endpoints across multiple regions. Each request is sent through a different regional gateway, effectively changing the source IP address to bypass IP-based blocking mechanisms.

Features

  • Spin up API Gateways across 10 AWS regions for maximum IP diversity
  • Automatic rotation through endpoints on each request
  • Support for both HTTP and HTTPS protocols
  • Real-time status monitoring with enable/disable toggle
  • Configurable target domain specification
  • Automatic resource cleanup when disabled
  • Built-in AWS credentials management

Usage

  1. Configure AWS credentials with API Gateway permissions in the extension interface
  2. Specify the target domain you wish to route traffic through
  3. Select the protocol (HTTP or HTTPS) based on your target
  4. Choose which AWS regions to utilize for the IP pool
  5. Click Enable to create API Gateway endpoints
  6. Send requests normally → traffic will automatically rotate through different IP addresses
  7. Click Disable when finished to clean up AWS resources

The extension is particularly useful for bypassing rate limiting, brute force protection, and WAF rules that implement IP-based blocking. All requests to the configured target domain are automatically intercepted and routed through the rotating gateway endpoints.

For more information see Bypassing IP Based Blocking Using AWS

Author

Author

David Yesland

Version

Version

2.0a

Rating

Rating

Popularity

Popularity

Last updated

Last updated

10 September 2025

Estimated system impact

Estimated system impact

Overall impact: Low

Memory
Low
CPU
Low
General
Low
Scanner
Low

You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.

You can view the source code for all BApp Store extensions on our GitHub page.

Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates.

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.

Go back to BappStore

Note:

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.