21. Web Application Testing Tools
21.2 Burp Suite: Proxy and Intercept
Burp Suite (Community Edition, free, ships with Kali) is the most-used web testing tool. Setup:
- Start Burp:
burpsuite(or from the Kali menu). Use the temporary project. - Proxy, Options: the proxy listens on
127.0.0.1:8080by default. - In Firefox, set the network proxy to
127.0.0.1:8080(the FoxyProxy add-on makes this one click). - Install Burp's CA certificate: browse to
http://burp, download the cert, and add it in Firefox so HTTPS sites work without warnings. - Proxy, Intercept: turn Intercept on, browse to DVWA, and watch requests stop in Burp.
Main Burp tabs:
| Tab | What it does |
|---|---|
| Proxy | Intercept and view every request/response |
| Target, Site map | A tree of everything you have browsed |
| Repeater | Send one request again and again, editing it each time |
| Intruder | Automate many requests with changing values (rate-limited in Community) |
| Decoder | Encode/decode URL, Base64, HTML |
| Comparer | Diff two responses |
Repeater is where you will spend most time: right-click a request, "Send to Repeater", change one value, hit Send, read the response. This is how you test one input at a time.
Ravindra Bagale's Tip
"Intercept is on" theun students visartat, aani mag "internet chalat nahi" mhantat – karan pratyek request Burp madhe thamblela asto. Kaam nasel tevha Intercept off theva; site map aani history tari bharat rahtat. Ha number ek confusion sagle navshike anubhavtat.
Lab
Set up Burp with Firefox and the CA certificate. Log in to DVWA through Burp, find the login request in the HTTP history, send it to Repeater, change the username, and observe the different response. Take a screenshot of the request and response side by side.