BURPSUITE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
PROXY SETUP#
# Default proxy 127.0.0.1:8080 # Firefox: Settings > Network > Manual proxy # Chrome: Use FoxyProxy extension # Install CA certificate http://burp -> CA Certificate Import into browser's certificate store
KEYBOARD SHORTCUTS#
Ctrl+I Send to Intruder Ctrl+R Send to Repeater Ctrl+U URL encode selection Ctrl+Shift+U URL decode selection Ctrl+B Base64 encode Ctrl+Shift+B Base64 decode Ctrl+H HTML encode Ctrl+Shift+H HTML decode Ctrl+F Find Ctrl+G Go to line Ctrl+Space Autocomplete Ctrl+Shift+V Paste from clipboard
PROXY TAB#
# Intercept - Toggle intercept on/off - Forward: send to server - Drop: discard request - Action: send to other tools # HTTP History - View all proxied requests - Filter by MIME type, status, etc. - Highlight interesting items # Options - Proxy listeners - Request interception rules - Response interception rules - Match and replace rules
INTRUDER TAB#
# Attack Types - Sniper: Single payload position, one at a time - Battering Ram: Same payload all positions simultaneously - Pitchfork: Multiple payload sets, one per position - Cluster Bomb: Multiple payload sets, all combinations # Position Markers Add §: Ctrl+A (or manually add §param§) # Payload Types - Simple list - Runtime file - Numbers (sequential, random) - Brute forcer - Dates - Null payloads - Character substitution - Recursive grep # Payload Processing - Add prefix/suffix - Encode (URL, Base64, Hash) - Match/Replace - Case modification # Example: Password Brute Force 1. Capture login request 2. Send to Intruder (Ctrl+I) 3. Clear § markers 4. Add § around password value 5. Set payload (wordlist) 6. Start attack 7. Sort by Length/Status to find valid
REPEATER TAB#
# Manual request manipulation - Edit request - Click Send - Analyze response - Good for testing single requests # Tips - Use < > arrows to navigate history - Right-click > Change request method - Right-click > Change body encoding
SEQUENCER TAB#
# Token analysis - Capture requests with tokens - Configure token location - Start capture - Analyze randomness quality # Analysis shows: - Overall quality - Character-level analysis - Bit-level analysis - FIPS tests
DECODER TAB#
# Encoding/Decoding - URL encoding - HTML encoding - Base64 - ASCII Hex - Hex - Gzip - Octal # Smart Decode - Auto-detect and decode
COMPARER TAB#
# Compare two items - Words view - Bytes view - Sync views for side-by-side
SCANNER (PRO)#
# Active Scan - Automatically test for vulnerabilities - Configure scope - View issues # Passive Scan - Analyzes proxied traffic - No additional requests # Scan Types - Crawl only - Audit only - Crawl and Audit
EXTENSIONS#
# Popular Extensions (BApp Store) - Logger++: Enhanced logging - Autorize: Authorization testing - JSON Web Tokens: JWT analysis - Param Miner: Hidden parameter discovery - Turbo Intruder: Fast Intruder alternative - CSRF Scanner: CSRF testing - Software Vulnerability Scanner - Retire.js: JS library vulnerabilities - CO2: Various testing tools # Install from BApp Store Extender > BApp Store > Install # Manual installation Extender > Extensions > Add
SCOPE CONFIGURATION#
# Target > Scope > Add - Include/Exclude URLs - Use regex patterns # Example patterns .*\.example\.com$ # All subdomains ^https://api\..* # All HTTPS API endpoints # Only show in-scope items Proxy > Options > Filter > Show only in-scope items
MATCH & REPLACE#
# Proxy > Options > Match and Replace # Use cases: - Remove security headers - Modify cookies - Add custom headers - Replace response content # Examples Match: X-Frame-Options:.* Replace: (empty) Match: Set-Cookie: (.*); Secure Replace: Set-Cookie: $1
SESSION HANDLING#
# Project options > Sessions - Session handling rules - Cookie jar - Macros for login sequences # Macro example (stay logged in): 1. Record login sequence 2. Create session rule 3. Run macro when session invalid
COLLABORATOR (PRO)#
# Out-of-band testing - DNS lookups - HTTP interactions - SMTP interactions # Use for: - Blind SSRF - Blind XXE - Blind SQL injection - DNS exfiltration
USEFUL FILTERS#
# Proxy History filters - Show only parameterized requests - Show only in-scope - Filter by MIME type - Filter by status code - Hide images/CSS/JS
ENGAGEMENT TOOLS#
Target > Right-click > Engagement tools - Find references - Discover content - Schedule task - Generate CSRF PoC
TESTING WORKFLOW#
1. Configure proxy and scope 2. Manual browsing (spider the app) 3. Review site map 4. Identify entry points 5. Test with Repeater (manual) 6. Test with Intruder (automated) 7. Run Scanner (Pro) 8. Document findings
COMMON TESTS#
# SQL Injection ' OR '1'='1 ' OR '1'='1'-- " OR "1"="1 # XSS <script>alert(1)</script> <img src=x onerror=alert(1)> javascript:alert(1) # Command Injection ; ls | whoami `id` # Path Traversal ../../../etc/passwd ....//....//....//etc/passwd # SSRF http://127.0.0.1 http://localhost http://169.254.169.254
TIPS#
- Use Target > Site map for overview - Color-code items in history - Add comments to requests - Use search across all tools - Export results for reporting - Save project regularly