官术网_书友最值得收藏!

Burp Proxy

Burp Suite has become the de facto standard for web application testing. Its many features provide nearly all of the tools required by a web penetration tester. The Pro version includes an automated scanner that can do active and passive scanning, and it has added configuration options in Intruder (Burp's fuzzing tool). Kali Linux includes the free version, which doesn't have scanning capabilities, nor does it offer the possibility of saving projects; also, it has some limitations on the fuzzing tool, Intruder. It can be accessed from Applications | Web Application Analysis | Web Application Proxies. Burp Suite is a feature-rich tool that includes a web spider, Intruder, and a repeater for automating customized attacks against web applications. I will go into greater depth on several Burp Suite features in later chapters.

Burp Proxy is a nontransparent proxy, and the first step that you need to take is to bind the proxy to a specific port and IP address and configure the web browser to use the proxy. By default, Burp listens on the 127.0.0.1 loopback address and the 8080 port number:

Make sure that you select a port that is not used by any other application in order to avoid any conflicts. Note the port and binding address and add these to the proxy settings of the browser.

By default, Burp Proxy only intercepts requests from the clients. It does not intercept responses from the server. If required, manually turn it on from the Options tab in Proxy, further down in the Intercept Server Responses section.

主站蜘蛛池模板: 辉南县| 资中县| 乌苏市| 唐河县| 柳河县| 新营市| 夏邑县| 龙井市| 安溪县| 平南县| 报价| 化隆| 淮阳县| 临颍县| 陵水| 西城区| 东至县| 榆林市| 安岳县| 行唐县| 巴东县| 丰都县| 葫芦岛市| 茶陵县| 平邑县| 平南县| 临洮县| 黔南| 赣榆县| 万全县| 中西区| 崇礼县| 胶州市| 延吉市| 汉川市| 太和县| 益阳市| 仪征市| 布尔津县| 武强县| 大渡口区|