← All cheat sheets

BURPSUITE-ADVANCED

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Advanced techniques, extensions, and workflows for Burp Suite Professional.

ESSENTIAL EXTENSIONS#

  Autorize
    - Automated authorization testing
    - Configure low-privilege session cookie in headers
    - Browse as high-privilege user; Autorize replays requests with low-priv cookie
    - Color codes: red (authz bypass), green (enforced), yellow (uncertain)

  Logger++
    - Advanced logging with filters and grep across all traffic
    - Export logs to CSV/JSON for offline analysis
    - Useful filters: response contains "password", status code 500
    - Regex filtering on request/response pairs

  Param Miner
    - Discovers hidden parameters and headers
    - Essential for cache poisoning and hidden functionality
    - Usage: right-click request -> Extensions -> Param Miner -> Guess headers/params
    - Finds unkeyed headers for web cache poisoning

  Hackvertor
    - Tag-based encoder/decoder within Repeater/Intruder
    - Nest encoding: <@base64><@url>payload<@/url><@/base64>
    - Auto-update hashes, lengths, timestamps in requests
    - Custom tags for complex encoding chains

  Active Scan++
    - Enhances Burp's active scanner with additional checks
    - Detects host header injection, cache poisoning, input transformation issues

  JSON Web Tokens (JWT Editor)
    - Decode, modify, and sign JWTs
    - Test for alg:none, key confusion, weak secrets
    - Generate signing keys for exploitation

  Turbo Intruder
    - Python-based high-speed Intruder alternative
    - Race condition testing with gate mechanism
    - Handles millions of requests with minimal memory
    - Example race condition script:
      def queueRequests(target, wordlists):
          engine = RequestEngine(endpoint=target.endpoint, concurrentConnections=30,
                                 requestsPerConnection=100, pipeline=False)
          for i in range(30):
              engine.queue(target.req, gate='race1')
          engine.openGate('race1')

  Upload Scanner
    - Tests file upload functionality for bypasses
    - Generates polyglot files, tests extension filtering
    - Content-type manipulation and magic byte injection

  InQL (GraphQL)
    - GraphQL introspection and attack surface mapping
    - Generates queries from schema
    - Batch query testing

MACROS AND SESSION HANDLING#

  Creating a Macro:
    1. Project Options -> Sessions -> Macros -> Add
    2. Select recorded requests that represent the session flow
    3. Define parameter extraction from responses (CSRF tokens, session IDs)
    4. Configure derived parameters between macro steps

  Session Handling Rules:
    1. Project Options -> Sessions -> Session Handling Rules -> Add
    2. Rule Actions:
       - Run a macro (e.g., re-authenticate before each scan request)
       - Check session is valid (define indicators)
       - Update current request with parameters from macro response
    3. Scope: define which tools and URLs the rule applies to
    4. Example flow:
       Macro: GET /csrf-token -> POST /login -> Extract session cookie
       Rule: Run macro if session invalid, update request cookies

  Multi-Step Authentication Macro:
    Step 1: GET /login (extract CSRF token)
    Step 2: POST /login with credentials + CSRF token (extract session cookie)
    Step 3: GET /dashboard (validate session is active)
    Configure: "If last response does not contain 'Welcome', re-run macro"

  Token Extraction in Macros:
    - Define custom parameter locations in response
    - Use regex or start/end delimiters
    - Derive parameters from one request to the next
    - Tolerate URL changes for dynamic endpoints

SCANNER TUNING#

  Scan Configuration:
    - Audit optimization:
      Speed: Faster -> fewer checks, Thorough -> comprehensive
      Issues reported: Minimize false positives vs. find everything
    - Crawl settings:
      Max crawl depth, max unique locations, login credentials
      Crawl strategy: Fastest, Faster, Normal, More complete, Most complete

  Custom Scan Profiles:
    - Create profiles for specific vulnerability classes
    - SQLi-only scan: disable all checks except SQL injection variants
    - XSS-only scan: focus on reflected/stored/DOM-based XSS
    - Save and reuse profiles across projects

  Scan Scope:
    - Include/exclude URL patterns
    - Exclude logout URLs to maintain session
    - Exclude static resources for speed
    - Example exclusions:
      *.css, *.js, *.png, *.jpg, *.gif, /logout, /signout

  Handling Scan Issues:
    - False positive: right-click -> "Mark as false positive"
    - Confidence levels: Certain, Firm, Tentative
    - Severity: High, Medium, Low, Information

INTRUDER ATTACK TYPES#

  Sniper:
    - Single payload set, one position at a time
    - Use for: fuzzing individual parameters, testing one field
    - Positions: $$param1$$, $$param2$$ tested sequentially

  Battering Ram:
    - Single payload set, all positions simultaneously
    - Use for: testing same value in multiple locations (e.g., CSRF token reuse)

  Pitchfork:
    - Multiple payload sets, one per position, in parallel
    - Use for: credential stuffing (username list + password list, paired 1:1)
    - Position 1 gets payload set 1, position 2 gets payload set 2

  Cluster Bomb:
    - Multiple payload sets, every combination tested
    - Use for: brute force all username/password combinations
    - Warning: combinatorial explosion with large lists
    - N1 * N2 total requests

  Payload Processing:
    - Add prefix/suffix
    - Encode (URL, Base64, hash)
    - Match/replace within payloads
    - Invoke Burp extension for custom processing
    - Skip if matches regex

  Resource Pool:
    - Control concurrent requests (avoid DoS)
    - Add delays between requests
    - Throttle to avoid rate limiting / WAF triggers

COLLABORATOR USAGE#

  Basics:
    - Burp Collaborator: out-of-band interaction detection
    - Generates unique subdomains: xyz123.burpcollaborator.net
    - Detects DNS, HTTP, and SMTP interactions

  Manual Testing:
    - Burp menu -> Burp Collaborator Client
    - Generate payloads -> Copy to clipboard
    - Insert into test inputs (headers, parameters, file names)
    - Poll for interactions

  Common Use Cases:
    - Blind SSRF: http://xyz123.burpcollaborator.net
    - Blind XXE:
      <!DOCTYPE foo [
        <!ENTITY xxe SYSTEM "http://xyz123.burpcollaborator.net">
      ]>
    - Blind SQL injection (out-of-band):
      '; EXEC master..xp_dirtree '//xyz123.burpcollaborator.net/a'--
    - Blind OS command injection:
      ; nslookup xyz123.burpcollaborator.net
    - Email header injection for SMTP interactions

  Private Collaborator Server:
    - Deploy your own for sensitive engagements
    - java -jar burp.jar --collaborator-server --collaborator-config=config.json

MATCH AND REPLACE RULES#

  Location: Proxy -> Options -> Match and Replace

  Common Rules:
    # Remove security headers (testing)
    Match:  X-Frame-Options: .*
    Replace: (empty)

    # Add custom header to all requests
    Match:  (empty, type: Request header)
    Replace: X-Custom-Header: test_value

    # Force HTTP to test for HTTPS enforcement
    Match:  https://
    Replace: http://

    # Modify User-Agent
    Match:  User-Agent: .*
    Replace: User-Agent: Mozilla/5.0 (custom scanner)

    # Remove CSP headers for XSS testing
    Match:  Content-Security-Policy: .*
    Replace: (empty)

    # Auto-update CSRF tokens (basic)
    Match:  csrf_token=OLD_VALUE
    Replace: csrf_token=NEW_VALUE

  Scope:
    - Apply to requests, responses, or both
    - Use regex for flexible matching
    - Can be enabled/disabled individually

ADVANCED TIPS AND WORKFLOWS#

  Bambdas (Burp 2024+):
    - Java lambda expressions for custom filtering in HTTP history
    - Filter Proxy history with code:
      return requestResponse.hasResponse() &&
             requestResponse.response().statusCode() == 403;
    - More powerful than built-in filters

  Scope Management:
    - Use advanced scope with URL-matching rules
    - Exclude common CDNs and third-party scripts
    - Include only target domains + subdomains

  Project Files:
    - Save entire project state for later analysis
    - Use project options files to share configurations
    - Import/export scan configs between team members

  Engagement Workflow:
    1. Spider/crawl the application
    2. Review sitemap, identify attack surface
    3. Configure session handling if needed
    4. Run passive scan on all captured traffic
    5. Active scan specific endpoints
    6. Manual testing with Repeater on interesting endpoints
    7. Use Intruder for fuzzing and brute force
    8. Check Collaborator for out-of-band interactions
    9. Generate report

  Keyboard Shortcuts:
    Ctrl+R  Send to Repeater
    Ctrl+I  Send to Intruder
    Ctrl+S  Send to Scanner
    Ctrl+Shift+R  Toggle Repeater
    Ctrl+Shift+I  Toggle Intruder
    Ctrl+Space  Send request (in Repeater)

  Tips:
    - Use response rendering to visualize reflected content
    - Compare responses side-by-side in Comparer
    - Use content discovery (Engagement tools) for hidden endpoints
    - Export findings in multiple formats for reports
    - Burp's embedded browser avoids TLS certificate issues
    - Use "Copy as curl command" for quick testing outside Burp