官术网_书友最值得收藏!

Burp Proxy

Burp Suite has become the de facto standard for web application testing. Its many features provide nearly all of the tools required by a web penetration tester. The Pro version includes an automated scanner that can do active and passive scanning, and it has added configuration options in Intruder (Burp's fuzzing tool). Kali Linux includes the free version, which doesn't have scanning capabilities, nor does it offer the possibility of saving projects; also, it has some limitations on the fuzzing tool, Intruder. It can be accessed from Applications | Web Application Analysis | Web Application Proxies. Burp Suite is a feature-rich tool that includes a web spider, Intruder, and a repeater for automating customized attacks against web applications. I will go into greater depth on several Burp Suite features in later chapters.

Burp Proxy is a nontransparent proxy, and the first step that you need to take is to bind the proxy to a specific port and IP address and configure the web browser to use the proxy. By default, Burp listens on the 127.0.0.1 loopback address and the 8080 port number:

Make sure that you select a port that is not used by any other application in order to avoid any conflicts. Note the port and binding address and add these to the proxy settings of the browser.

By default, Burp Proxy only intercepts requests from the clients. It does not intercept responses from the server. If required, manually turn it on from the Options tab in Proxy, further down in the Intercept Server Responses section.

主站蜘蛛池模板: 肥西县| 无锡市| 南陵县| 南和县| 大田县| 普陀区| 金阳县| 临高县| 韶关市| 胶州市| 石嘴山市| 余庆县| 新乡县| 邢台县| 翁源县| 简阳市| 金秀| 榆树市| 宝山区| 土默特右旗| 剑阁县| 泰兴市| 古蔺县| 江川县| 宕昌县| 隆尧县| 平顺县| 高青县| 安达市| 石家庄市| 佳木斯市| 沈阳市| 务川| 华蓥市| 唐河县| 廊坊市| 广水市| 庆元县| 龙门县| 行唐县| 铜川市|