Learn the basics of how to use Burp Suite, the popular web application penetration testing tool.
Overview
Syllabus
Introduction
- Learning how to use Burp Suite effectively
- What you should know
- Course disclaimer
- What is Burp Suite?
- Getting to know Burp Suite
- Proxying web traffic
- Using Burp Suite as a proxy
- Setting up additional targets
- Crawling the website
- Finding hidden webpages
- Understanding message content
- Finding missing content
- Intercepting bank transactions
- Exploiting headers
- Inserting an SQL injection via Burp Suite
- Saving request messages for further exploitation
- Injecting commands into messages
- Introducing the Intruder
- Manipulating cookies
- The four Intruders
- Using CO2 to integrate SQLMap
- Next steps
Taught by
Malcolm Shore