• Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
AnonyViet - English Version
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office
No Result
View All Result
AnonyViet - English Version
No Result
View All Result

Web Pentest – Lesson 1: An overview of Burp Suite

AnonyViet by AnonyViet
January 25, 2023
in Security
0

Nowadays, creating and developing a website is not difficult for everyone. Creating a website can be of great help to everyone and especially in the current 4.0 era. In addition, the Covid-19 pandemic has made our tendency to go online on websites. But have you ever wondered if the website you build is safe enough for you and the customers accessing the system? What if a bad guy attacks your Website?

Join the channel Telegram of the AnonyViet 👉 Link 👈

So today Anonyviet will bring you a series on the security of your Website system. You will be playing the role of a bad guy and attack on your website (Penttest) and from there will find out the error on the system and how to fix it.

Pentest Burpsuite Support Software Overview

Installation Requirements:

About BurpSuite

Burpsuite currently has many different versions. Each version has quite different features and interfaces. In this article, Anonyviet will introduce this Burpsuite 2021.4.3 version.

After installation, you open Burp Suite and you will have the same interface as below.

Web Pentest - Lesson 1: An overview of Burp Suite 13

How to use Burp Suite

In the Dashboard interface, there will be information about the Tasks running on the website that need to be pentested. The EventLog below shows the detected vulnerabilities. The information in the EventLog frame is quite important, there are many errors related to the certificate, the connection error is also displayed here. Makes it easier to spot and solve it faster.

Next is the Target section

Web Pentest - Lesson 1: An overview of Burp Suite 14

In Target, there will be information about the subsites of that website that are allowed to access, requests can be made on these sites, you can press the > button in each site, to view it in a tree, there will be more intuitive view of the target.

Also in the Target, can serve to filter requests more quickly than in the Scope subtab.

Next is the Proxy tab interface, this is an extremely important part in Burp Suite. The HTTP history tab will save the history of requests made during real-time manipulation right on the application or Website. You can directly view the request, response and edit it.

From the Proxy tab, you can select a request and send this request to other tools in Burp Suite that support such as Repeater, Intruder, Comparer, …

In the latest version that I introduce, Burpsuite has integrated the Chromium browser, which is very convenient and saves you from having to manually configure it on other browsers.

To open Chromium, click Open Browser like the image below.

Web Pentest - Lesson 1: An overview of Burp Suite 15

When the Chromium browser is launched, you go to any website, Anonyviet.Com for example, and see the recorded requests in the HTTP Proxy tab. If not, your Intercept is off. Click to turn it on.

The next tab is Intruder. Used a lot to BruteForce Username, Password, Directory or test IDOR…

Web Pentest - Lesson 1: An overview of Burp Suite 16

Next to the Intruder tab, it is the Repeater, which is an indispensable component for every time we pentest. Here, it allows us to edit any component of the request, from methods, headers, parameters, etc. After editing the request, you click Send to send the request to the server and receive the response.

Web Pentest - Lesson 1: An overview of Burp Suite 17

I say this is an indispensable ingredient, not just saying. That’s because attacking a target requires us to send payloads in different locations. The same is true of BurpSuite.

Changing the request itself like this allows us to try out all the payloads we have, look for reflected inputs in the response (when looking for XSS vulnerabilities), or see the results returned when we type the payload as SQL injection,…, and to do those tasks, Repeater is the best solution to do it.

This part is quite important, so I will go into detail in the next articles. Remember to follow along.

Next is the Sequencer tab, which is used to analyze the complexity of the token generation algorithms in the website. See if it’s easy to guess.

Web Pentest - Lesson 1: An overview of Burp Suite 18

Next is Tab Decoder used to encode or decode character types such as MD5, AES, BASE64 …

Web Pentest - Lesson 1: An overview of Burp Suite 19

Tab Comparer, used to compare different requests and responses, sent by you through tabs such as proxy tabs or target tabs. You can send by right-clicking the request and selecting send to comparer.

Web Pentest - Lesson 1: An overview of Burp Suite 20

The Logger tab, as the name suggests, will save all requests executed in the Burp Suite.

Web Pentest - Lesson 1: An overview of Burp Suite 21

The Extender tab is an interesting tab, it allows you to add new Burp existing extensions, or add extensions developed by yourself. I will go into more detail in the next posts.

Web Pentest - Lesson 1: An overview of Burp Suite 22

Here are some basics that you must be familiar with before the pentesting process begins. You can learn more on your own, it will be very helpful for beginners. In the next articles we will learn about Bruteforce techniques, collect information, etc. Hope you will watch and support.

Summary Series :

Good luck
TMQ.

The article achieved: 5/5 – (100 votes)

Tags: BurpLessonoverviewPentestSuiteweb
Previous Post

Lesson 256: Calculated Field/Item in Excel

Next Post

Need to immediately delete Play Store on Windows 11 if you don’t want to get Virus

AnonyViet

AnonyViet

Related Posts

How to implement Shellcode Injection attack technique with Autoit
Security

How to implement Shellcode Injection attack technique with Autoit

March 14, 2025
How to exploit the holy hole of Hijacking on Windows
Security

How to exploit the holy hole of Hijacking on Windows

March 8, 2025
Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery
Security

Hamamal: Shellcode execution technique from afar to overcome Antivirus's discovery

February 10, 2025
Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile
Security

Snov.io Email Finder: Search emails with only company name/domain name/LinkedIn profile

December 14, 2024
Capsolver: Automatic solution solution for business
Security

Capsolver: Automatic solution solution for business

December 12, 2024
Seekr: Collect & manage OSINT data
Security

Seekr: Collect & manage OSINT data

November 22, 2024
Next Post
Need to immediately delete Play Store on Windows 11 if you don’t want to get Virus

Need to immediately delete Play Store on Windows 11 if you don't want to get Virus

0 0 votes
Article Rating
Subscribe
Login
Notify of
guest

guest

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments

Recent News

Guide to comment on the constitution amendment on VNEID

Guide to comment on the constitution amendment on VNEID

May 21, 2025
Tips to fix the file is open in another program

Tips to fix the file is open in another program

May 21, 2025
7 ways to release RAM to accelerate your Windows computer

7 ways to release RAM to accelerate your Windows computer

May 21, 2025
Discover Supermix – Smart playlist on YouTube Music

Discover Supermix – Smart playlist on YouTube Music

May 20, 2025
Guide to comment on the constitution amendment on VNEID

Guide to comment on the constitution amendment on VNEID

May 21, 2025
Tips to fix the file is open in another program

Tips to fix the file is open in another program

May 21, 2025
7 ways to release RAM to accelerate your Windows computer

7 ways to release RAM to accelerate your Windows computer

May 21, 2025
AnonyViet - English Version

AnonyViet

AnonyViet is a website share knowledge that you have never learned in school!

We are ready to welcome your comments, as well as your articles sent to AnonyViet.

Follow Us

Contact:

Email: anonyviet.com[@]gmail.com

Main Website: https://anonyviet.com

Recent News

Guide to comment on the constitution amendment on VNEID

Guide to comment on the constitution amendment on VNEID

May 21, 2025
Tips to fix the file is open in another program

Tips to fix the file is open in another program

May 21, 2025
  • Home
  • Home 2
  • Home 3
  • Home 4
  • Home 5
  • Home 6
  • Next Dest Page
  • Sample Page

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply
No Result
View All Result
  • Home
  • News
  • Software
  • Knowledge
  • MMO
  • Tips
  • Security
  • Network
  • Office

©2024 AnonyVietFor Knowledge kqxs hôm nay xem phim miễn phí SHBET bongdaso