- Hands-On Application Penetration Testing with Burp Suite
- Carlos A. Lozano Dhruv Shah Riyaz Ahemed Walikar
- 180字
- 2021-07-02 12:16:36
Why Burp Suite? Let's cover some groundwork!
Burp Suite is a proxy and it allows you to intercept and tamper each and every request that goes from the browser to the application server. This gives the tester a huge capability to pentest all the avenues of the application, as it shows all the available endpoints. It works as a middleware. The biggest advantage it gives you is the capability to bypass client-side validations.
It is a smart tool that keeps track of your browsing history and also manages the site structure, giving you a better picture of what is available and what the newly discovered avenues are. The core advantage of Burp is that it allows you to forward HTTP requests to different Burp tools and carry out the required task. It could be repeating or automating an attack, decoding certain parameters, or comparing two or more different requests. Burp gives the user a capability to understand different formats by decoding the parameters at runtime for the user; for example, decoding ViewState parameters, beautifying JSON requests, and so on.
- Android應用安全實戰:Frida協議分析
- INSTANT Netcat Starter
- 網絡安全保障能力研究
- 白帽子講Web安全(紀念版)
- 黑客攻防技巧
- 數字安全藍皮書:本質屬性與重要特征
- 軟件開發安全之道:概念、設計與實施
- 硬黑客:智能硬件生死之戰
- 網絡運維親歷記 (網絡運維紀實文學)
- 數據安全架構設計與實戰
- Mastering Linux Security and Hardening
- INSTANT Kali Linux
- ATT&CK與威脅獵殺實戰
- Instant OSSEC Host-based Intrusion Detection System
- CPK通向賽博安全之路:理論與實踐CPK Solution to Cyber Security:Theory and Practice