SlideShare a Scribd company logo
Hack Like a Pro
with Burp Suite
/pavanw3b
What do you learn?
I’m a boring geek
Burp Suite is your best friend
Some really cool tweaks
~$ whoami
pavanw3b
Yet another w3bAppSec guy
break-fix-repeat
Security Engineer @
ServiceNow
Who’s an expert here?
More than an interception
proxy
Burp Suite
Start like a Pro
$ java –jar –Xmx4G
/path/burpsuite.jar
• Let burp use up to 4GB
• Default can be as low as 128MB
• But not more than 4GB
Better Proxy-ing
Global
Just Firefox
Moody - FoxyProxy
Focus on Target
It’s your Desktop
Set better Scope
Compare Site
maps
Drop out-of-
scope Options > Connections
Better Filter Target
See In-scope
items
Hide not-found
Demo
Playing around Proxy
Play around Message Analytics
Can also contain XML, AMF & View
State
Intercept Request
Intercept Response
HTTP history: Params & Filter
Unhide hidden form fields
Exploiting with Intruder
Send lots of data & make sense of
response
Username Enumeration, Directory
Fuzzing – XSS, SQLi, Path traversal
Add payload: FuzzDB, WebAppURLs,
OWASP DirBuster
Demo: Save & Load attack Config
Stay calm & use
Scanner
Passive Scanning
Active Scanning
Use wise!
Crawl -> Scan
Demo
Don’t make too fast
Be in-scope
Never miss anything - Repeater
Scratchpad
Demo
Change the way you want it
Try OPTIONS
The good Spider
Create lots of Pollution
Form Submissions
Do after manual Crawl
Demo
Some are only on Prod: robots.txt
Careful - Delete all users
Control threads
All about tokens - Sequencer
Test how random it is..
Session, CSRF, Password reset etc
Min 100 tokens required
Find the secret - Decode
No Key - No Security
Encode != Security
Demo
Send to Decoder
Confused? Use Comparer
Compare
responses
Blind SQLi
Compare by
Words
ByteByte: Computationally costly
Demo: Compare 2 responses
Engagement Tools
Search
Find in Comments, Scripts, Ref
Analyze Target
Discover Content
Wanna add? Extender
Jython, JRuby etc
BApp Store
java.lang.OutOfMemoryError?
java -XX:MaxPermSize=1G -jar
burpsuite.jar
Maintenance
Save State
Save in-scope only
Restore State
Don’t restore from untrusted sources
Auto backup
Schedule Task: Save State - Creates only
1file
Some more if you need
Right click & you got all
Shortcuts: Options > Misc > Hotkeys
References & Reads
Burp Suite Essentials by Akash Mahajan
10 Unbeatable Features of Burp Suite
Pro
Official Documentation
Pen Testing with Burp Suite
Real life tips & tricks
Am I really
boring?
Pavan
http://pavanw3b.com
fb/pavanw3b | @pavanw3b

More Related Content

PDF
Basics of Metaprogramming in Ruby
PPT
STNMFD Introduction
DOCX
Tom's resume rev.July 2015
PDF
Five Reasons to Become a DJ
DOCX
type of testing
PPTX
What is a MOOC?
PPT
Innovating processes
PDF
Bug bounty null_owasp_2k17
Basics of Metaprogramming in Ruby
STNMFD Introduction
Tom's resume rev.July 2015
Five Reasons to Become a DJ
type of testing
What is a MOOC?
Innovating processes
Bug bounty null_owasp_2k17

Similar to Hack like a pro with burp suite by pavanw3b (20)

PPSX
Coding standard
PPTX
Sql Injections With Real Life Scenarious
PDF
Symfony Performance
PPT
Heavy Web Optimization: Backend
PDF
PPT
WE18_Performance_Up.ppt
PPT
How to improve problem solving skills
PPTX
antoanthongtin_Lesson 3- Software Security (1).pptx
PPT
Intro To Mashups
KEY
Site Performance - From Pinto to Ferrari
PPTX
Burp Suite Starter
PPTX
SDOC-9384E354D357952A32C22C63F420335F-12-16-SI.pptx
PPT
bh-us-02-murphey-freebsd
PPTX
Practical SPARQL Benchmarking
PPT
Pentesting Using Burp Suite
PDF
Volker Fröhlich - How to Debug Common Agent Issues
PDF
Introduction to Windows Dictionary Attacks
PDF
Performance profiling and testing of symfony application 2
PDF
Ethical hacking mind map
PPT
Automated Unit Testing
Coding standard
Sql Injections With Real Life Scenarious
Symfony Performance
Heavy Web Optimization: Backend
WE18_Performance_Up.ppt
How to improve problem solving skills
antoanthongtin_Lesson 3- Software Security (1).pptx
Intro To Mashups
Site Performance - From Pinto to Ferrari
Burp Suite Starter
SDOC-9384E354D357952A32C22C63F420335F-12-16-SI.pptx
bh-us-02-murphey-freebsd
Practical SPARQL Benchmarking
Pentesting Using Burp Suite
Volker Fröhlich - How to Debug Common Agent Issues
Introduction to Windows Dictionary Attacks
Performance profiling and testing of symfony application 2
Ethical hacking mind map
Automated Unit Testing

More from Pavan M (6)

PDF
Conquering the command line for code hackers
PPTX
Sh00t - nullhyd version
PDF
Sh00t - defcon presentation
PPTX
OWASP A7 and A8
PPTX
OWASP A1 - Injection | The art of manipulation
PPTX
Hacker's jargons
Conquering the command line for code hackers
Sh00t - nullhyd version
Sh00t - defcon presentation
OWASP A7 and A8
OWASP A1 - Injection | The art of manipulation
Hacker's jargons

Recently uploaded (20)

PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Big Data Technologies - Introduction.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Unlocking AI with Model Context Protocol (MCP)
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PPTX
Cloud computing and distributed systems.
PDF
cuic standard and advanced reporting.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
Dropbox Q2 2025 Financial Results & Investor Presentation
Mobile App Security Testing_ A Comprehensive Guide.pdf
The AUB Centre for AI in Media Proposal.docx
Building Integrated photovoltaic BIPV_UPV.pdf
The Rise and Fall of 3GPP – Time for a Sabbatical?
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Big Data Technologies - Introduction.pptx
Digital-Transformation-Roadmap-for-Companies.pptx
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
MYSQL Presentation for SQL database connectivity
Unlocking AI with Model Context Protocol (MCP)
20250228 LYD VKU AI Blended-Learning.pptx
Cloud computing and distributed systems.
cuic standard and advanced reporting.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Review of recent advances in non-invasive hemoglobin estimation
Agricultural_Statistics_at_a_Glance_2022_0.pdf
“AI and Expert System Decision Support & Business Intelligence Systems”

Hack like a pro with burp suite by pavanw3b

Editor's Notes

  • #10: ----- Meeting Notes (9/11/15 20:02) ----- Image blur