Ravindra BagaleCourses & study guides

21. Web Application Testing Tools

21.2 Burp Suite: Proxy and Intercept

Burp Suite (Community Edition, free, ships with Kali) is the most-used web testing tool. Setup:

  1. Start Burp: burpsuite (or from the Kali menu). Use the temporary project.
  2. Proxy, Options: the proxy listens on 127.0.0.1:8080 by default.
  3. In Firefox, set the network proxy to 127.0.0.1:8080 (the FoxyProxy add-on makes this one click).
  4. Install Burp's CA certificate: browse to http://burp, download the cert, and add it in Firefox so HTTPS sites work without warnings.
  5. Proxy, Intercept: turn Intercept on, browse to DVWA, and watch requests stop in Burp.

Main Burp tabs:

Tab What it does
Proxy Intercept and view every request/response
Target, Site map A tree of everything you have browsed
Repeater Send one request again and again, editing it each time
Intruder Automate many requests with changing values (rate-limited in Community)
Decoder Encode/decode URL, Base64, HTML
Comparer Diff two responses

Repeater is where you will spend most time: right-click a request, "Send to Repeater", change one value, hit Send, read the response. This is how you test one input at a time.

Ravindra Bagale's Tip

"Intercept is on" theun students visartat, aani mag "internet chalat nahi" mhantat – karan pratyek request Burp madhe thamblela asto. Kaam nasel tevha Intercept off theva; site map aani history tari bharat rahtat. Ha number ek confusion sagle navshike anubhavtat.

Lab

Set up Burp with Firefox and the CA certificate. Log in to DVWA through Burp, find the login request in the HTTP history, send it to Repeater, change the username, and observe the different response. Take a screenshot of the request and response side by side.