← All cheat sheets

BURPSUITE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

PROXY SETUP#

# Default proxy
127.0.0.1:8080

# Firefox: Settings > Network > Manual proxy
# Chrome: Use FoxyProxy extension

# Install CA certificate
http://burp -> CA Certificate
Import into browser's certificate store

KEYBOARD SHORTCUTS#

Ctrl+I          Send to Intruder
Ctrl+R          Send to Repeater
Ctrl+U          URL encode selection
Ctrl+Shift+U    URL decode selection
Ctrl+B          Base64 encode
Ctrl+Shift+B    Base64 decode
Ctrl+H          HTML encode
Ctrl+Shift+H    HTML decode
Ctrl+F          Find
Ctrl+G          Go to line
Ctrl+Space      Autocomplete
Ctrl+Shift+V    Paste from clipboard

PROXY TAB#

# Intercept
- Toggle intercept on/off
- Forward: send to server
- Drop: discard request
- Action: send to other tools

# HTTP History
- View all proxied requests
- Filter by MIME type, status, etc.
- Highlight interesting items

# Options
- Proxy listeners
- Request interception rules
- Response interception rules
- Match and replace rules

INTRUDER TAB#

# Attack Types
- Sniper: Single payload position, one at a time
- Battering Ram: Same payload all positions simultaneously
- Pitchfork: Multiple payload sets, one per position
- Cluster Bomb: Multiple payload sets, all combinations

# Position Markers
Add §: Ctrl+A (or manually add §param§)

# Payload Types
- Simple list
- Runtime file
- Numbers (sequential, random)
- Brute forcer
- Dates
- Null payloads
- Character substitution
- Recursive grep

# Payload Processing
- Add prefix/suffix
- Encode (URL, Base64, Hash)
- Match/Replace
- Case modification

# Example: Password Brute Force
1. Capture login request
2. Send to Intruder (Ctrl+I)
3. Clear § markers
4. Add § around password value
5. Set payload (wordlist)
6. Start attack
7. Sort by Length/Status to find valid

REPEATER TAB#

# Manual request manipulation
- Edit request
- Click Send
- Analyze response
- Good for testing single requests

# Tips
- Use < > arrows to navigate history
- Right-click > Change request method
- Right-click > Change body encoding

SEQUENCER TAB#

# Token analysis
- Capture requests with tokens
- Configure token location
- Start capture
- Analyze randomness quality

# Analysis shows:
- Overall quality
- Character-level analysis
- Bit-level analysis
- FIPS tests

DECODER TAB#

# Encoding/Decoding
- URL encoding
- HTML encoding
- Base64
- ASCII Hex
- Hex
- Gzip
- Octal

# Smart Decode
- Auto-detect and decode

COMPARER TAB#

# Compare two items
- Words view
- Bytes view
- Sync views for side-by-side

SCANNER (PRO)#

# Active Scan
- Automatically test for vulnerabilities
- Configure scope
- View issues

# Passive Scan
- Analyzes proxied traffic
- No additional requests

# Scan Types
- Crawl only
- Audit only
- Crawl and Audit

EXTENSIONS#

# Popular Extensions (BApp Store)
- Logger++: Enhanced logging
- Autorize: Authorization testing
- JSON Web Tokens: JWT analysis
- Param Miner: Hidden parameter discovery
- Turbo Intruder: Fast Intruder alternative
- CSRF Scanner: CSRF testing
- Software Vulnerability Scanner
- Retire.js: JS library vulnerabilities
- CO2: Various testing tools

# Install from BApp Store
Extender > BApp Store > Install

# Manual installation
Extender > Extensions > Add

SCOPE CONFIGURATION#

# Target > Scope > Add
- Include/Exclude URLs
- Use regex patterns

# Example patterns
.*\.example\.com$     # All subdomains
^https://api\..*      # All HTTPS API endpoints

# Only show in-scope items
Proxy > Options > Filter > Show only in-scope items

MATCH & REPLACE#

# Proxy > Options > Match and Replace
# Use cases:
- Remove security headers
- Modify cookies
- Add custom headers
- Replace response content

# Examples
Match: X-Frame-Options:.*
Replace: (empty)

Match: Set-Cookie: (.*); Secure
Replace: Set-Cookie: $1

SESSION HANDLING#

# Project options > Sessions
- Session handling rules
- Cookie jar
- Macros for login sequences

# Macro example (stay logged in):
1. Record login sequence
2. Create session rule
3. Run macro when session invalid

COLLABORATOR (PRO)#

# Out-of-band testing
- DNS lookups
- HTTP interactions
- SMTP interactions

# Use for:
- Blind SSRF
- Blind XXE
- Blind SQL injection
- DNS exfiltration

USEFUL FILTERS#

# Proxy History filters
- Show only parameterized requests
- Show only in-scope
- Filter by MIME type
- Filter by status code
- Hide images/CSS/JS

ENGAGEMENT TOOLS#

Target > Right-click > Engagement tools
- Find references
- Discover content
- Schedule task
- Generate CSRF PoC

TESTING WORKFLOW#

1. Configure proxy and scope
2. Manual browsing (spider the app)
3. Review site map
4. Identify entry points
5. Test with Repeater (manual)
6. Test with Intruder (automated)
7. Run Scanner (Pro)
8. Document findings

COMMON TESTS#

# SQL Injection
' OR '1'='1
' OR '1'='1'--
" OR "1"="1

# XSS
<script>alert(1)</script>
<img src=x onerror=alert(1)>
javascript:alert(1)

# Command Injection
; ls
| whoami
`id`

# Path Traversal
../../../etc/passwd
....//....//....//etc/passwd

# SSRF
http://127.0.0.1
http://localhost
http://169.254.169.254

TIPS#

- Use Target > Site map for overview
- Color-code items in history
- Add comments to requests
- Use search across all tools
- Export results for reporting
- Save project regularly