Book description
Discover the secrets of web application pentesting using Burp Suite, the best tool for the job
In Detail
This book aims to impart the skills of a professional Burp user to empower you to successfully perform various kinds of tests on any web application of your choice. It begins by acquainting you with Burp Suite on various operating systems and showing you how to customize the settings for maximum performance. You will then get to grips with SSH port forwarding and SOCKS-based proxies. You will also get hands-on experience in leveraging the features of Burp tools such as Target, Proxy, Intruder, Scanner, Repeater, Spider, Sequencer, Decoder, and more. You will then move on to searching, extracting, and matching patterns for requests and responses, and you will learn how to work with upstream proxies and SSL certificates. Next, you will dive into the world of Burp Extensions and also learn how to write simple extensions of your own in Java, Python, and Ruby.
As a professional tester, you will need to be able to report your work, safeguard it, and sometimes even extend the tools that you are using; you will learn how to do all this in the concluding chapters of this book.
What You Will Learn
- Get to grips with the user-driven workflow so that you can test any kind of web application
- Get acquainted with the use of each of the components in Burp?Target, Proxy, Intruder, Scanner, and Repeater
- Search, extract, and match patterns for requests and responses using response extraction rules, URL-matching rules, and Grep - Match
- Set up and test SSL-enabled applications without any errors
- Intercept SSL traffic from all kinds of web and mobile applications
- Develop customized Burp Extensions to suit your needs using Java, Python, and Ruby
Table of contents
-
Burp Suite Essentials
- Table of Contents
- Burp Suite Essentials
- Credits
- About the Author
- Acknowledgments
- About the Reviewers
- www.PacktPub.com
- Preface
- 1. Getting Started with Burp
- 2. Configuring Browsers to Proxy through Burp
- 3. Setting the Scope and Dealing with Upstream Proxies
- 4. SSL and Other Advanced Settings
- 5. Using Burp Tools As a Power User – Part 1
- 6. Using Burp Tools As a Power User – Part 2
- 7. Searching, Extracting, Pattern Matching, and More
- 8. Using Engagement Tools and Other Utilities
-
9. Using Burp Extensions and Writing Your Own
- Setting up the Python runtime for Burp Extensions
- Setting up the Ruby environment for Burp Extensions
- Loading and installing a Burp Extension from the Burp App Store
- Loading and installing a Burp Extension manually
- Managing Burp Extensions
- Writing our own Burp Extensions
- Noteworthy Burp Extensions
- Summary
- 10. Saving Securely, Backing Up, and Other Maintenance Activities
- 11. Resources, References, and Links
- Index
Product information
- Title: Burp Suite Essentials
- Author(s):
- Release date: November 2014
- Publisher(s): Packt Publishing
- ISBN: 9781783550111
You might also like
book
Burp Suite Cookbook
Get hands-on experience in using Burp Suite to execute attacks and perform web assessments Key Features …
book
Burp Suite Cookbook - Second Edition
Find and fix security vulnerabilities in your web applications with Burp Suite Key Features Set up …
book
A Complete Guide to Burp Suite: Learn to Detect Application Vulnerabilities
Use this comprehensive guide to learn the practical aspects of Burp Suite—from the basics to more …
book
Hands-On Application Penetration Testing with Burp Suite
Test, fuzz, and break web applications and services using Burp Suite's powerful capabilities Key Features Master …