Burp Suite Essentials
eBook - ePub

Burp Suite Essentials

  1. 144 pages
  2. English
  3. ePUB (mobile friendly)
  4. Available on iOS & Android
eBook - ePub

Burp Suite Essentials

Book details
Book preview
Table of contents
Citations

About This Book

This book aims to impart the skills of a professional Burp user to empower you to successfully perform various kinds of tests on any web application of your choice. It begins by acquainting you with Burp Suite on various operating systems and showing you how to customize the settings for maximum performance. You will then get to grips with SSH port forwarding and SOCKS-based proxies. You will also get hands-on experience in leveraging the features of Burp tools such as Target, Proxy, Intruder, Scanner, Repeater, Spider, Sequencer, Decoder, and more. You will then move on to searching, extracting, and matching patterns for requests and responses, and you will learn how to work with upstream proxies and SSL certificates. Next, you will dive into the world of Burp Extensions and also learn how to write simple extensions of your own in Java, Python, and Ruby.

As a professional tester, you will need to be able to report your work, safeguard it, and sometimes even extend the tools that you are using; you will learn how to do all this in the concluding chapters of this book.

Frequently asked questions

Simply head over to the account section in settings and click on “Cancel Subscription” - it’s as simple as that. After you cancel, your membership will stay active for the remainder of the time you’ve paid for. Learn more here.
At the moment all of our mobile-responsive ePub books are available to download via the app. Most of our PDFs are also available to download and we're working on making the final remaining ones downloadable now. Learn more here.
Both plans give you full access to the library and all of Perlego’s features. The only differences are the price and subscription period: With the annual plan you’ll save around 30% compared to 12 months on the monthly plan.
We are an online textbook subscription service, where you can get access to an entire online library for less than the price of a single book per month. With over 1 million books across 1000+ topics, we’ve got you covered! Learn more here.
Look out for the read-aloud symbol on your next book to see if you can listen to it. The read-aloud tool reads text aloud for you, highlighting the text as it is being read. You can pause it, speed it up and slow it down. Learn more here.
Yes, you can access Burp Suite Essentials by Akash Mahajan in PDF and/or ePUB format, as well as other popular books in Computer Science & Application Development. We have over one million books available in our catalogue for you to explore.

Information

Year
2014
ISBN
9781783550111
Edition
1

Burp Suite Essentials


Table of Contents

Burp Suite Essentials
Credits
About the Author
Acknowledgments
About the Reviewers
www.PacktPub.com
Support files, eBooks, discount offers, and more
Why subscribe?
Free access for Packt account holders
Preface
What this book covers
What you need for this book
Who this book is for
Conventions
Reader feedback
Customer support
Errata
Piracy
Questions
1. Getting Started with Burp
Starting Burp from the command line
Specifying memory size for Burp
Specifying the maximum memory Burp is allowed to use
Ensuring that IPv4 is allowed
Working with other JVMs
Summary
2. Configuring Browsers to Proxy through Burp
Configuring widely used browsers to proxy through Burp Suite
Microsoft Internet Explorer
Google Chrome
Mozilla Firefox
Fine-grained proxy configuration
Setting up FoxyProxy
Mozilla Plug-n-Hack extension
Exclusive Firefox profile
Summary
3. Setting the Scope and Dealing with Upstream Proxies
Multiple ways to add targets to the scope
Loading a list of targets from a file
Scope and Burp Suite tools
Scope inclusion versus exclusion
Dropping out-of-scope requests
Dealing with upstream proxies and SOCKS proxies
Types of proxies supported by Burp
Working with SOCKS proxies
Using SSH tunneling as a SOCKS proxy
Setting up Burp to be a proxy server for other devices
Summary
4. SSL and Other Advanced Settings
Importing the Burp certificate in Mozilla Firefox
Importing the Burp certificate in Microsoft IE and Google Chrome
Installing the Burp certificate in iOS or Android
SSL pass-through
Invisible Proxy
Summary
5. Using Burp Tools As a Power User – Part 1
Target
Site map compare
Proxy
The Message Analysis tab
Actions on the intercepted requests
Response interception and modification
Using the Proxy history tab
Intruder
Scanner
Scanning optimization and requests
When to scan
Repeater
Summary
6. Using Burp Tools As a Power User – Part 2
Spidering
Sequencer
Analysis of the tokens
Sample analysis
Decoder
Comparer
Alerts
Summary
7. Searching, Extracting, Pattern Matching, and More
Filtering
Illustration
Matching
Grep - Match and Grep - Extract
Summary
8. Using Engagement Tools and Other Utilities
Search
Target Analyzer
Content Discovery
Task Scheduler
CSRF proof of concept Generator
Summary
9. Using Burp Extensions and Writing Your Own
Setting up the Python runtime for Burp Extensions
Setting up the Ruby environment for Burp Extensions
Loading and installing a Burp Extension from the Burp App Store
Using BApp files
Loading and installing a Burp Extension manually
Managing Burp Extensions
Memory issues with Burp Extensions
Writing our own Burp Extensions
A simple Burp Extension in Python
Noteworthy Burp Extensions
Summary
10. Saving Securely, Backing Up, and Other Maintenance Activities
Saving and restoring a state
Automatic backups
Scheduled tasks
Logging all activities
Summary
11. Resources, References, and Links
Primary references
Learning about Burp
Web application security testing with Burp
Miscellaneous security testing tutorials with Burp Suite
Pentesting thick clients
Testing mobile applications for web security using Burp Suite
Extensions references
Books
Summary
Index

Burp Suite Essentials

Copyright © 2014 Packt Publishing
All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews.
Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing, and its dealers and distributors will be held liable for any damages caused or alleged to be caused directly or indirectly by this book.
Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information.
First published: November 2014
Production reference: 2111214
Published by Packt Publishing Ltd.
Livery Place
35 Livery Street
Birmingham B3 2PB, UK.
ISBN 978-1-78355-011-1
www.packtpub.com

Credits

Author
Akash Mahajan
Reviewers
Luca De Fulgentis
Rejah Rehim
David Shaw
Commissioning Editor
Anthony Albuquerque
Acquisition Editor
Harsha Bharwani
Content Development Editor
Neeshma Ramakrishnan
Technical Editor
Mrunal M. Chavan
Copy Editor
Sarang Chari
Project Coordinator
Rashi Khivansara
Proofreaders
Simran Bhogal
Ameesha Green
Lucy Rowland
Indexers
Monica Ajmera Mehta
Tejal Soni
Graphics
Abhinash Sahu
Production Coordinator
Manu Joseph
Cover Work
Manu Joseph

About the Author

Akash Mahajan is "That Web Application Security Guy." He has more than 10 years of experience in application and network security. Before starting his own company, he was a technical lead for one of the leading American commercial security software companies specializing in endpoint security. He then started working on the security of the web infrastructure for the Government of India.
He is the founder and community manager at null - The Open Security Community, where he has made major contributions in making null a national-level group and null Bangalore the biggest and most vibrant chapter.
He is currently a ch...

Table of contents

  1. Burp Suite Essentials