- Hands-On Application Penetration Testing with Burp Suite
- Carlos A. Lozano Dhruv Shah Riyaz Ahemed Walikar
- 180字
- 2021-07-02 12:16:36
Why Burp Suite? Let's cover some groundwork!
Burp Suite is a proxy and it allows you to intercept and tamper each and every request that goes from the browser to the application server. This gives the tester a huge capability to pentest all the avenues of the application, as it shows all the available endpoints. It works as a middleware. The biggest advantage it gives you is the capability to bypass client-side validations.
It is a smart tool that keeps track of your browsing history and also manages the site structure, giving you a better picture of what is available and what the newly discovered avenues are. The core advantage of Burp is that it allows you to forward HTTP requests to different Burp tools and carry out the required task. It could be repeating or automating an attack, decoding certain parameters, or comparing two or more different requests. Burp gives the user a capability to understand different formats by decoding the parameters at runtime for the user; for example, decoding ViewState parameters, beautifying JSON requests, and so on.
- 網(wǎng)絡(luò)安全與管理
- unidbg逆向工程:原理與實(shí)踐
- 工業(yè)互聯(lián)網(wǎng)安全防護(hù)與展望
- Kali Linux Social Engineering
- 電子支付的規(guī)制結(jié)構(gòu)配置研究
- 工業(yè)物聯(lián)網(wǎng)安全
- 同態(tài)密碼學(xué)原理及算法
- 數(shù)據(jù)安全與隱私計(jì)算(第3版)
- 零信任網(wǎng)絡(luò):在不可信網(wǎng)絡(luò)中構(gòu)建安全系統(tǒng)(第2版)
- Mastering Reverse Engineering
- 黑客攻防實(shí)戰(zhàn)從入門到精通
- 網(wǎng)絡(luò)安全大數(shù)據(jù)分析與實(shí)戰(zhàn)
- 網(wǎng)絡(luò)空間安全:拒絕服務(wù)攻擊檢測(cè)與防御
- Cybersecurity Threats,Malware Trends,and Strategies
- 交換機(jī)·路由器·防火墻(第2版)