Burp Suite
Burp Suite is the intercepting proxy and the central tool of web hacking. It sits between the browser and the server, letting you view, modify, and replay every request. Mastering Burp is essential for web pentesting and bug bounty (see the Web area and bb-*).
The workflow
Section titled “The workflow”Proxy intercepts browser <-> server traffic; the basis of everythingTarget site map (sitemap) and working scopeRepeater resend and modify requests by hand -> test vulns by iteratingIntruder automate attacks (parameter fuzzing, brute force, enumeration)Decoder/Comparer encode/decode and compare responsesExtensions (BApp) extend Burp (Autorize, Param Miner, Logger++, Turbo Intruder)Initial setup
Section titled “Initial setup”- browser pointed at Burp's proxy (127.0.0.1:8080) + Burp's CA certificate installed -> to intercept HTTPS without certificate errors- define the SCOPE (only what's authorized) so you don't touch anything out (see bb-scope)- use Burp's embedded browser to start quicklyRepeater (the workhorse)
Section titled “Repeater (the workhorse)”- send a request to Repeater (Ctrl+R) and modify it as many times as needed- test SQLi, XSS, IDOR, SSRF... by changing a parameter and watching the response- the basis of MANUAL testing: understand how the app responds to each changeIntruder (automation)
Section titled “Intruder (automation)”Sniper one payload in one position (fuzzing a parameter)Battering ram same payload in several positionsPitchfork several payloads in parallel (e.g. paired user+pass)Cluster bomb all combinations (credential brute force)# in Community, Intruder is throttled; Pro removes the limitEssential extensions
Section titled “Essential extensions”Autorize detects access-control/IDOR flaws (see web-api, web-logic)Param Miner discovers hidden parameters/headersLogger++ advanced logging and search of all trafficTurbo Intruder high-speed attacks/race conditions (see web-race)JWT Editor manipulate JWT tokens (see web-session, crypto-pki)Blue Team / use
Section titled “Blue Team / use”- Burp is the center of web pentesting: Proxy to view, Repeater to test by hand, Intruder to automate.
- Setting the scope well avoids touching the unauthorized (Reading the scope & rules); install the CA for HTTPS.
- Extensions (Autorize, Param Miner) multiply its reach; it maps to the whole Web area.
- The Web Security Academy (free) is the best place to learn Burp (and the base of the BSCP, Burp Suite Certified (BSCP)).
Tips and gotchas
Section titled “Tips and gotchas”- Set the scope first and enable “show only in-scope” so you don’t drown in third-party noise.
- Common mistake: forgetting Community’s Intruder is throttled; for real brute force use Turbo Intruder or Pro.
- Save the project and use Repeater with named tabs; send anything you’ll tweak to Repeater.
- Learn the shortcuts (Ctrl+R to Repeater) and key extensions (Autorize for IDOR, Logger++).
Testing checklist
Section titled “Testing checklist”- Proxy configured + CA installed (HTTPS) + scope defined
- Map the site (Target/sitemap)
- Repeater for manual testing of each parameter
- Intruder for fuzzing/brute force (appropriate mode)
- Key extensions (Autorize, Param Miner, Logger++)
- Decoder/Comparer for encoding and diffs
- Work only within the authorized scope