官术网_书友最值得收藏!

Configuring Burp Suite

Before starting an application penetration test, the system that will be used to attack the end application must be prepared. This involves configuring Burp Suite to become the interception proxy for various clients and traffic sources.

As with scoping for targets, it is important to reduce noise in the data we collect. We will use target whitelisting techniques, and work with the Burp Target feature to filter and reduce the clutter that testing modern applications can introduce.

Burp, or Burp Suite, is a graphical tool for testing web applications for security flaws. The tool is written in Java and was created by Dafydd Stuttard under the name of PortSwigger. Burp Suite is now actively developed by his company PortSwigger Ltd., which is based out of the United Kingdom.

Burp is available in two variants: the free version, called the Community Edition, and the Professional version. The Community Edition lacks several features and speed enhancements that the Professional variant provides.

Throughout this book, we will be using the Professional version of Burp to navigate our way through the chapters and the hands-on exercises.

We will cover the following topics in this chapter:

  • Getting to know Burp Suite
  • Setting up proxy listeners
  • Managing multiple proxy listeners
  • Working with non-proxy aware clients
  • Creating target scopes in Burp Suite
  • Working with target exclusions
  • Quick settings before beginning

主站蜘蛛池模板: 论坛| 沾益县| 九龙县| 阿鲁科尔沁旗| 涪陵区| 上思县| 灵宝市| 成武县| 乾安县| 新兴县| 曲阳县| 东兴市| 佛教| 六安市| 清镇市| 齐齐哈尔市| 铜山县| 通山县| 蛟河市| 玉溪市| 马公市| 广灵县| 葫芦岛市| 扎鲁特旗| 滦南县| 汝州市| 高州市| 万宁市| 贡觉县| 宾阳县| 灌云县| 呼和浩特市| 宜阳县| 齐齐哈尔市| 宿迁市| 扎兰屯市| 内丘县| 石嘴山市| 奈曼旗| 德庆县| 太仓市|