Skip to content

Burp Suite

Burp Suite is the intercepting proxy and the central tool of web hacking. It sits between the browser and the server, letting you view, modify, and replay every request. Mastering Burp is essential for web pentesting and bug bounty (see the Web area and bb-*).

Proxy intercepts browser <-> server traffic; the basis of everything
Target site map (sitemap) and working scope
Repeater resend and modify requests by hand -> test vulns by iterating
Intruder automate attacks (parameter fuzzing, brute force, enumeration)
Decoder/Comparer encode/decode and compare responses
Extensions (BApp) extend Burp (Autorize, Param Miner, Logger++, Turbo Intruder)
- browser pointed at Burp's proxy (127.0.0.1:8080) + Burp's CA certificate installed
-> to intercept HTTPS without certificate errors
- define the SCOPE (only what's authorized) so you don't touch anything out (see bb-scope)
- use Burp's embedded browser to start quickly
- send a request to Repeater (Ctrl+R) and modify it as many times as needed
- test SQLi, XSS, IDOR, SSRF... by changing a parameter and watching the response
- the basis of MANUAL testing: understand how the app responds to each change
Sniper one payload in one position (fuzzing a parameter)
Battering ram same payload in several positions
Pitchfork several payloads in parallel (e.g. paired user+pass)
Cluster bomb all combinations (credential brute force)
# in Community, Intruder is throttled; Pro removes the limit
Autorize detects access-control/IDOR flaws (see web-api, web-logic)
Param Miner discovers hidden parameters/headers
Logger++ advanced logging and search of all traffic
Turbo Intruder high-speed attacks/race conditions (see web-race)
JWT Editor manipulate JWT tokens (see web-session, crypto-pki)
  • Burp is the center of web pentesting: Proxy to view, Repeater to test by hand, Intruder to automate.
  • Setting the scope well avoids touching the unauthorized (Reading the scope & rules); install the CA for HTTPS.
  • Extensions (Autorize, Param Miner) multiply its reach; it maps to the whole Web area.
  • The Web Security Academy (free) is the best place to learn Burp (and the base of the BSCP, Burp Suite Certified (BSCP)).
  • Set the scope first and enable “show only in-scope” so you don’t drown in third-party noise.
  • Common mistake: forgetting Community’s Intruder is throttled; for real brute force use Turbo Intruder or Pro.
  • Save the project and use Repeater with named tabs; send anything you’ll tweak to Repeater.
  • Learn the shortcuts (Ctrl+R to Repeater) and key extensions (Autorize for IDOR, Logger++).
  • Proxy configured + CA installed (HTTPS) + scope defined
  • Map the site (Target/sitemap)
  • Repeater for manual testing of each parameter
  • Intruder for fuzzing/brute force (appropriate mode)
  • Key extensions (Autorize, Param Miner, Logger++)
  • Decoder/Comparer for encoding and diffs
  • Work only within the authorized scope