Burp Suite
Last updated
Last updated
Professional / Community 1.7.36 | Releases (portswigger.net)
Attacks Types
Attack Type | Description |
Sniper | Uses a single payload list; Replaces one position at a time |
Battering Ram | Uses a single payload list; Replaces all positions at the same time |
Pitchfork | Each position has a corresponding payload list; So if there are two positions to be modified they each get their own payload list. |
Cluster Bomb | Uses each payload list and tries different combinations for each position |
Free Extensions to use
Software Vulnerability
→ [ CVE’s ]
Retire.js
→ [ JQuery Flaws]
JSON Web Tokensor JWT editor
→ [JWT pentest]
param miner
→ [Web Cache Poisoning]
Decoder Improved
→ https://portswigger.net/bappstore/0a05afd37da44adca514acef1cdde3b9
Autorize
- [AC Bugs]
● Backslash Powered Scanner
- Advanced payloads while active scanner
● Google Authenticator
- Automation in 2FA
● Java Serial Killer
- payload generation tool for Java object deserialization
● Handy Collaborator
- OOB requests while manual test using Repeater
● HUNT Suite
- Identify common parameters for known vulnerabilities
● J2EEScan
- Scanner for Java based application
● Logger++
- Keeps logs of everything
● SAML Editor/SAML Encoder-Decoder/SAML Raider
- SAML requests
● `WSDLER/WSDL Wizard ``- Web service automatio
Burp Collaborator
● A network service which helps to discover Blind vulnerabilities such as SQL Injection, XML Injection, Cross-Site Scripting etc. ● Uses a specially crafted dedicated domain name and reports as an issue such as External Service Interaction, SQL Injection etc.