Burp Suite
Intercepting proxy and toolkit for testing web applications by hand.
Burp Suite is an intercepting proxy for testing web applications by hand. It sits between your browser and the target, so you can read, replay and change every request the browser sends. The free Community edition is enough to learn on, and Professional adds an automated scanner. This page covers installing Burp, getting your browser traffic into it, and the two tools you will use most.
Use it only on systems you own or are authorized to test.
Installing Burp Suite
Download the installer for your platform from PortSwigger, or use a package manager. The official build ships with its own Java runtime, so there is nothing else to set up.
# download the installer for your OS from portswigger.net/burp sudo apt install burpsuite # Kali brew install --cask burp-suite # macOS
Your first capture
Burp only sees traffic once the browser is pointed at it and the certificate is trusted. Do these three steps once, then browse the target as a normal user.
Set the proxy
Point the browser HTTP and HTTPS proxy at 127.0.0.1:8080, Burp default listener.
Trust the CA
Browse to http://burp, download the CA certificate and trust it so HTTPS decrypts without warnings.
Set the scope
Add the application to scope and restrict logging to in-scope items so the history stays clean.
# Method URL Status 1 GET /login 200 2 POST /login 302 3 GET /account/1024 200
Every request lands in the HTTP history as a row. Click one to read the full request and response, and right-click to send it to Repeater or Intruder.
Repeater: change one thing and resend
Repeater sends one request over and over with your edits, so you can change a single value and read the exact effect. This is where you prove an access-control bug by swapping an id and comparing what comes back.
GET /account/1024 HTTP/1.1
Host: lab-host
Cookie: session=abc123
# in Repeater: change 1024 to 1025, resend, compare the responseIntruder and its attack types
Intruder automates variations of a request across one or more marked positions. The attack type decides how payloads are placed, so pick it to match the shape of what you are testing.
| Attack type | Use it for |
|---|---|
| Sniper | One payload set across one position at a time |
| Battering ram | The same payload in every position at once |
| Pitchfork | Parallel payload sets, one per position, in step |
| Cluster bomb | Every combination of several payload sets |
Sniper covers most parameter testing. Cluster bomb is the brute-force shape, trying every username against every password.
Extensions and the scanner
The BApp store adds free extensions such as Autorize for access-control testing and Param Miner for hidden parameters. The scanner, in Professional, crawls and audits automatically, but treat its output as leads to verify by hand. Community has no scanner and a throttled Intruder, which is still plenty to learn on.
Learn Repeater and the HTTP history first. The habits that find real bugs live there, and they all work in the free Community edition.
Install
# download the installer for your OS from portswigger.net/burp sudo apt install burpsuite # Kali brew install --cask burp-suite # macOS # the official build bundles its own Java runtime
Example
# 1. set the browser HTTP/HTTPS proxy to 127.0.0.1:8080 # 2. visit http://burp and install the CA certificate # 3. browse the target; requests appear in Proxy > HTTP history
Run this against your own lab or systems you have written permission to test — nothing else.