16
About me :- @U7KAR5H null Bhopal Monthly Meet May 2016 Utkarsh Bhargava Not a Hacker Chapter Lead @ null Bhopal

Introduction to burp suite

Embed Size (px)

Citation preview

Page 1: Introduction to burp suite

● About me :- ● @U7KAR5H

null Bhopal Monthly MeetMay 2016 ● Utkarsh

Bhargava● Not a Hacker ● Chapter Lead @ null

Bhopal

Page 2: Introduction to burp suite

INTRODUCTION TO BURP

Page 3: Introduction to burp suite

MORE THAN JUST A SILLY NAME• Burp is a proxy-based web application testing tool

• De-facto standard for manual web app. Testing

• Free and paid-for versions available

• Other options are available– OWASP ZAP – upcoming Open Source alternative– Telerik Fiddler – Primarily windows based alternative

Page 4: Introduction to burp suite

WHY PROXIES?• Intercept and modify traffic between client and server

• Bypass any JavaScript restrictions

• Access hidden fields

• Modify headers

• Modify cookies

Page 5: Introduction to burp suite

BURP TOUR – SITEMAP

Page 6: Introduction to burp suite

BURP TOUR – SCOPE

Page 7: Introduction to burp suite

BURP TOUR INTERCEPT

Page 8: Introduction to burp suite

BURP TOUR – HTTP HISTORY

Page 9: Introduction to burp suite

BURP TOUR - SPIDER

Page 10: Introduction to burp suite

BURP TOUR - SCANNER

Page 11: Introduction to burp suite

BURP TOUR - INTRUDER

Page 12: Introduction to burp suite

BURP TOUR - REPEATER

Page 13: Introduction to burp suite

BURP TOUR - SEQUENCER

Page 14: Introduction to burp suite

BURP TOUR - DECODER

Page 15: Introduction to burp suite

BURP TOUR – OPTIONS

Page 16: Introduction to burp suite

Thats all !!!

● Any Questions

● Thank You