Burp Suite Cheatsheet for Web Application Testing

📱 Mobile Security Tips

Sarah Chen — iOS Security Specialist

What is Burp Suite?

Burp Suite is a popular web application security testing tool that is widely used by security analysts and penetration testers. It provides various utilities for scanning, crawling, analyzing, and exploiting web applications for vulnerabilities.

Installation

Burp Suite can be downloaded from the official PortSwigger website. It is available in different editions including Community, Professional, and Enterprise.

Basic Syntax

The core capabilities of Burp Suite can be accessed through its graphical user interface (GUI). However, several command-line tools can be utilized for automated tasks within Burp.

Discovery

Spidering a Website

python burp-spider.py -u http://targetsite.com

This command starts the spidering process on the specified URL.

Scanning

Active Scan

burpsuite -c active -t http://targetsite.com

This command initiates an active scan against the target site.

Exploitation

Intruder Usage

python burp-intruder.py -u http://targetsite.com/path -d "param=value"

Use this command to set up an Intruder attack.

Analysis

Repeater Functionality

To resend requests and manipulate parameters, use the repeater to analyze how the application responds.

Evasion

Setting Up Interceptors

You can configure the intercept settings in Burp’s Proxy settings to capture and modify HTTP requests.

Reporting

Generate Reports

burpsuite -r report.html

This command will generate a report of the findings.

Quick Reference Table

Flag Description
-u Specify the target URL
-c Specify the type of scan

Pro Tips

  • Always start with a spider to gather endpoints before scanning.
  • Use session handling rules in Burp to maintain login sessions across requests.
  • Fuzzing with the Intruder can identify unexpected inputs leading to vulnerabilities.

Real-World Examples

For instance, during a recent pentest, using Burp’s Intruder allowed us to uncover SQL injection flaws effortlessly by automating parameter manipulation.