Skip to main content

Burp suite

What is Burpsuite you ask? Burp Suite is a Java based Web Penetration Testing framework.

It has become an industry standard suite of tools used by information security professionals to identify vulnerabilities and verify attack vectors for web-based applications.

In its simplest form, Burpsuite can be classified as an Interception Proxy.

A penetration tester configures their Internet browser to route traffic through the proxy which then acts as a sort of Man In The Middle by capturing and analyzing each request and response to and from the target web application.

Individual HTTP requests can be paused, manipulated and replayed back to the web server for targeted analysis of parameter specific injection points.

Injection points can be specified for manual as well as automated fuzzing attacks to discover potentially unintended application behaviors, crashes and error messages.

  >> BURPSUITE: SOURCE

  Burpsuite is created by: PortSwigger Web Security

It is available as a free download with limited but extremely capable functionality.

However, the commercial suite is affordably priced and well worth the investment if you are serious about web penetration testing.

You can obtain a licensed copy here: https://portswigger.net/buy/

  Burp is easy to use and provides the administrators full control to combine advanced manual techniques with automation for efficient testing.

Burp can be easily configured and it contains features to assist even the most experienced testers with their work.
  _________________________

Comments

Popular posts from this blog

How to Connect Two Computers Via Crossover Ethernet Cable?

In this tutorial we are going to show you how to transfer data from one computer to another. We need to PC/Laptop and a crossover cable to transfer data. PC 1 Step1: Go to “Open Networking and Sharing Center“. Step2: Click on “Local Area Connection“. Step3: Now click on “Properties“. Step4: Double click on “Internet Protocol Version 4(TCP/IPv6)“. Step5: Click on “Use the following IP address:” and enter the IP address: as 192.168.1.1 and just give a click onSubnet mask. Once done click “Ok” and close it.   PC 2 Step1: Go to “Open Networking and Sharing Center“. Step2: Click on “Local Area Connection“. Step3: Now click on “Properties“. Step4: Double click on “Internet Protocol Version 4(TCP/IPv6)“. Step5: Click on “Use the following IP address:” and enter the IP address: as 192.168.1.2 and just give a click onSubnet mask. Once done click “Ok” and close it. Now  two computers are connected. To share files we need to give access to our drives, so fol...

What is a Phreaking ?

A phreak is someone who breaks into the telephone network illegally, typically to make free long-distance phone calls or to tap phone lines. The term is now sometimes used to include anyone who breaks or tries to break the security of any network. Recently, the phone companies have introduced new security safeguards, making phreaking more difficult. Phreaking is a slang term coined to describe the activity of a culture of people who study, experiment with, or explore telecommunication systems, such as equipment and systems connected to public telephone networks. The term phreak is a sensational spelling of the word freak with the ph- from phone, and may also refer to the use of various audio frequencies to manipulate a phone system. Phreak, phreaker, or phone phreak are names used for and by individuals who participate in phreaking. The term first referred to groups who had reverse engineered the system of tones used to route long-distance calls. By re-creating thes...

Denial of service (DoS) attack Trojans

These Trojans give the attacker the power to start a distributed denial of service (DDoS) attack if there are enough victims. The main idea is that if you have 200 infected ADSL users and you attack the victim simultaneously from each, this will generate HEAVY traffic (more than the victim's bandwidth can carry, in most cases), causing its access to the Internet to shut down. WinTrinoo is a DDoS tool that has recently become very popular; through it, An attacker who has infected many ADSL users can cause major Internet sites to shut down; Early examples of this date back to February 2000, when a number of prominent e-commerce sites such as Amazon, CNN, E*Trade, Yahoo and eBay were attacked. Another variation of a DoS Trojan is the mail-bomb Trojan, where the main aim is to infect as many machines as possible and simultaneously attack specific email address/addresses with random subjects and contents that cannot be filtered. Again, a DoS Trojan is similar to a virus,...