Web Proprietary, with a free Community edition Linux, macOS, Windows

Burp Suite

Intercepting proxy and toolkit for testing web applications by hand.

>_ Official siteportswigger.net/burp Visit

Burp Suite is an intercepting proxy for testing web applications by hand. It sits between your browser and the target, so you can read, replay and change every request the browser sends. The free Community edition is enough to learn on, and Professional adds an automated scanner. This page covers installing Burp, getting your browser traffic into it, and the two tools you will use most.

Scope

Use it only on systems you own or are authorized to test.

Installing Burp Suite

Download the installer for your platform from PortSwigger, or use a package manager. The official build ships with its own Java runtime, so there is nothing else to set up.

bash
# download the installer for your OS from portswigger.net/burp
sudo apt install burpsuite      # Kali
brew install --cask burp-suite  # macOS

Your first capture

Burp only sees traffic once the browser is pointed at it and the certificate is trusted. Do these three steps once, then browse the target as a normal user.

Set the proxy

Point the browser HTTP and HTTPS proxy at 127.0.0.1:8080, Burp default listener.

Trust the CA

Browse to http://burp, download the CA certificate and trust it so HTTPS decrypts without warnings.

Set the scope

Add the application to scope and restrict logging to in-scope items so the history stays clean.

Proxy > HTTP history
#  Method  URL              Status
1  GET     /login           200
2  POST    /login           302
3  GET     /account/1024    200

Every request lands in the HTTP history as a row. Click one to read the full request and response, and right-click to send it to Repeater or Intruder.

Repeater: change one thing and resend

Repeater sends one request over and over with your edits, so you can change a single value and read the exact effect. This is where you prove an access-control bug by swapping an id and comparing what comes back.

http
GET /account/1024 HTTP/1.1
Host: lab-host
Cookie: session=abc123
# in Repeater: change 1024 to 1025, resend, compare the response

Intruder and its attack types

Intruder automates variations of a request across one or more marked positions. The attack type decides how payloads are placed, so pick it to match the shape of what you are testing.

Attack typeUse it for
SniperOne payload set across one position at a time
Battering ramThe same payload in every position at once
PitchforkParallel payload sets, one per position, in step
Cluster bombEvery combination of several payload sets

Sniper covers most parameter testing. Cluster bomb is the brute-force shape, trying every username against every password.

Extensions and the scanner

The BApp store adds free extensions such as Autorize for access-control testing and Param Miner for hidden parameters. The scanner, in Professional, crawls and audits automatically, but treat its output as leads to verify by hand. Community has no scanner and a throttled Intruder, which is still plenty to learn on.

Next step

Learn Repeater and the HTTP history first. The habits that find real bugs live there, and they all work in the free Community edition.

Install

shell
# download the installer for your OS from portswigger.net/burp
sudo apt install burpsuite      # Kali
brew install --cask burp-suite  # macOS
# the official build bundles its own Java runtime

Example

shell
# 1. set the browser HTTP/HTTPS proxy to 127.0.0.1:8080
# 2. visit http://burp and install the CA certificate
# 3. browse the target; requests appear in Proxy > HTTP history
Authorized use only

Run this against your own lab or systems you have written permission to test — nothing else.