Burp Suite

Informational

Burp Suite

Definition

Burp Suite is the reference tool for web application security testing, developed by PortSwigger. It works as an HTTP/S proxy that intercepts, modifies and replays requests between the browser and the server. It includes tools such as Repeater (replaying requests), Intruder (fuzzing), Scanner (automatic vulnerability detection) and extensions such as Logger++ and Autorize.

Impact

Intercepting and modifying HTTP/S requests in real timeAutomating attacks with Intruder (parameter fuzzing)Automatic vulnerability detection with the ScannerAnalyzing the attack surface of web applicationsExtensible with plugins (BApp Store) for specific needs

Examples

Typical Burp Suite workflow

1) Configure the browser to use Burp as a proxy (127.0.0.1:8080). 2) Browse the application to map the attack surface (Target > Site Map). 3) Intercept interesting requests (Proxy > Intercept). 4) Send requests to Repeater to modify them and test variations. 5) Use Intruder to automate parameter fuzzing. 6) Install extensions such as Autorize for automatic authorization testing.

Essential Burp Suite extensions

The most popular extensions for bug bounty are: Autorize (automatic authentication/authorization testing), Logger++ (advanced request logging), Param Miner (hidden parameter discovery), Turbo Intruder (ultra-fast fuzzing for race conditions), Active Scan++ (scanner improvements), and JSON Web Token Attacker (JWT attacks).

Practice Burp Suite with real labs

Apply what you've learned in safe environments based on real bug bounty reports.

See practice labs
2,482

hunters training

62

labs from real hacks

1,630

completions

$14,790

paid out for these bugs

11 flags captured this week·Real hacks from HackerOne · YesWeHack · Bugcrowd·No commitment·Free Academy
Free · no account

The checklist I run on every new target

47 checks ordered by cost: first what can get you in trouble, then the cheap stuff, and finally the expensive stuff — which is where the big bounties are. I'll send it to your inbox right now.

Unsubscribe in one click, from any email.

BBLabs · bug bounty training

Stop reading about bugs and start hunting them

Create your free account and practice on labs based on real hacks that paid out thousands of euros. The Academy is free forever.

No card · free Academy · cancel anytime