<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>Burp &#8211; AnonyViet &#8211; English Version</title>
	<atom:link href="https://en.anonyviet.com/tag/burp/feed/" rel="self" type="application/rss+xml" />
	<link>https://en.anonyviet.com</link>
	<description>The most popular website for sharing information technology, computer networks, and security knowledge. Stay up to date with the hottest news and tips</description>
	<lastBuildDate>Fri, 17 Apr 2026 21:58:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.1</generator>

<image>
	<url>https://en.anonyviet.com/wp-content/uploads/2023/01/cropped-ico-logo-75x75-1.png</url>
	<title>Burp &#8211; AnonyViet &#8211; English Version</title>
	<link>https://en.anonyviet.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How to intercept traffic using Burp Suite to analyze HTTP/HTTPS</title>
		<link>https://en.anonyviet.com/how-to-intercept-traffic-using-burp-suite-to-analyze-http-https/</link>
					<comments>https://en.anonyviet.com/how-to-intercept-traffic-using-burp-suite-to-analyze-http-https/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Fri, 17 Apr 2026 21:58:30 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[analyze]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[HTTPHTTPS]]></category>
		<category><![CDATA[intercept]]></category>
		<category><![CDATA[Suite]]></category>
		<category><![CDATA[Traffic]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=21837</guid>

					<description><![CDATA[Quick Answer: To block HTTP/HTTPS traffic using Burp Suiteyou need to install Burp, configure the browser to use a proxy 127.0.0.1:8080then install the certificate Burp CA into the browser. When the feature is enabled Interceptevery request from the browser will go through Burp before reaching the server, allowing you to view and edit data. 📢 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><strong>Quick Answer:</strong> To block HTTP/HTTPS traffic using <strong>Burp Suite</strong>you need to install Burp, configure the browser to use a proxy <strong>127.0.0.1:8080</strong>then install the certificate <strong>Burp CA</strong> into the browser. When the feature is enabled <strong>Intercept</strong>every request from the browser will go through Burp before reaching the server, allowing you to view and edit data.</p>
<div class="av-telegram-box" style="margin:16px 0;">
<div style="border:1px solid #dbeafe; background:linear-gradient(135deg,#eff6ff 0%,#ecfeff 100%); border-radius:14px; padding:14px 16px; box-shadow:0 4px 14px rgba(0,0,0,.06); text-align:center;">
<p> <span style="display:inline-block; margin-right:4px;">📢</span> Join the channel <span style="color:#2563eb;">Telegram</span> belong to <span style="color:#0f766e;">AnonyViet</span></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" target="_blank" rel="noopener nofollow" style="display:inline-flex; align-items:center; justify-content:center; gap:8px; background:#229ED9; color:#fff; text-decoration:none; font-weight:700; font-size:14px; padding:10px 14px; border-radius:10px; box-shadow:0 4px 10px rgba(34,158,217,.25);"><br />
<span>👉 Go to Telegram AnonyViet</span><br />
</a></p>
<p>  Update new articles, cool tools and IT tips fastest</p>
</div>
</div>
<p>When working with <strong>Web Security</strong>observing and editing HTTP requests is an extremely important skill. This is how security experts detect vulnerabilities such as <em>SQL Injection, XSS, Authentication Bypass</em> or debug API.</p>
<p>One of the most popular tools today is <strong>Burp Suite</strong> – web security testing toolkit by <strong>PortSwigger</strong> develop.</p>
<p>In this article, AnonyViet will guide you how to set up Burp Suite to:</p>
<ul>
<li>Block all web traffic from browsers</li>
<li>Analyze HTTP request/response</li>
<li>Decrypt HTTPS traffic with TLS Certificate</li>
</ul>
<p><img post-id="21837" fifu-featured="1" fetchpriority="high" decoding="async" class="aligncenter wp-image-34004 size-full" src="https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard.jpg" alt="How to intercept traffic using Burp Suite to analyze HTTP/HTTPS" title="How to intercept traffic using Burp Suite to analyze HTTP/HTTPS" width="901" height="452" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 20" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard.jpg 400w, https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard-300x150.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard-768x385.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard-360x180.jpg 360w, https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard-750x376.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard-120x60.jpg 120w" sizes="(max-width: 901px) 100vw, 901px"/></p>
<h2 id="ftoc-burp-suite-la-gi" class="ftwp-heading">What is Burp Suite?</h2>
<p><strong>Burp Suite</strong> (often referred to as <strong>Burp</strong>) is a graphical tool that helps test Web application security.</p>
<p>It works like one <strong>intermediary proxy (MITM – Man in the Middle)</strong> between browser and server. When the request goes through Burp, you can:</p>
<ul>
<li>View all HTTP requests</li>
<li>Edit parameters</li>
<li>Header analysis</li>
<li>Replay request</li>
<li>API security testing</li>
</ul>
<p>Burp Suite has many versions:</p>
<ul>
<li><strong>Community Edition</strong> &#8211; free of charge</li>
<li><strong>Professional</strong> – for pentester</li>
<li><strong>Enterprise</strong> – large-scale security testing</li>
</ul>
<p>This article uses version <strong>Community Edition</strong>.</p>
<h2 id="ftoc-nhung-gi-chung-ta-se-thuc-hien" class="ftwp-heading">What we will do</h2>
<p>To block traffic with Burp Suite, you will take 3 main steps:</p>
<ol>
<li>Download and install Burp Suite</li>
<li>Configure the browser to use Burp&#8217;s proxy</li>
<li>Install a TLS certificate to block HTTPS</li>
</ol>
<h2 id="ftoc-buoc-1-tai-va-cai-dat-burp-suite" class="ftwp-heading">Step 1: Download and install Burp Suite</h2>
<p>You can download Burp Suite Community at PortSwigger&#8217;s official site:</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fportswigger.net%2Fburp%2Fcommunitydownload" target="_blank" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">https://portswigger.net/burp/communitydownload</a></p>
<p>Note:</p>
<ul>
<li>Burp Suite requests <strong>Java Runtime</strong></li>
<li>Supports Windows, Linux and macOS</li>
</ul>
<p>After installing and opening Burp Suite, you will see the project initialization interface:</p>
<p><img decoding="async" class="size-full wp-image-33990 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-1.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 18" width="722" height="464" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 21" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-1.jpg 722w, https://anonyviet.com/wp-content/uploads/2021/09/burp-1-300x193.jpg 300w" sizes="(max-width: 722px) 100vw, 722px"/></p>
<p>If you don&#8217;t want to save the project:</p>
<ul>
<li>Press <strong>Next</strong></li>
<li>Then choose <strong>Start Burp</strong></li>
</ul>
<p><img decoding="async" class="size-full wp-image-33991 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-2.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 19" width="711" height="453" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 22" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-2.jpg 711w, https://anonyviet.com/wp-content/uploads/2021/09/burp-2-300x191.jpg 300w" sizes="(max-width: 711px) 100vw, 711px"/></p>
<p>The main interface of Burp Suite will appear:</p>
<p><img decoding="async" class="size-full wp-image-33992 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-3.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 20" width="1085" height="539" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 23" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-3.jpg 1085w, https://anonyviet.com/wp-content/uploads/2021/09/burp-3-300x149.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/burp-3-1024x509.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/burp-3-768x382.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/burp-3-360x180.jpg 360w, https://anonyviet.com/wp-content/uploads/2021/09/burp-3-750x373.jpg 750w" sizes="(max-width: 1085px) 100vw, 1085px"/></p>
<h2 id="ftoc-buoc-2-cau-hinh-proxy-cho-trinh-duyet" class="ftwp-heading">Step 2: Configure Proxy for the browser</h2>
<p>In order for Burp to block requests, the browser must send traffic through Burp&#8217;s proxy.</p>
<p>In this example I use <strong>Firefox</strong>.</p>
<p>Open settings:</p>
<p><strong>about:preferences#general</strong></p>
<p>Scroll down to the section <strong>Network Settings</strong> and press <strong>Settings</strong>.</p>
<p><img decoding="async" class="size-full wp-image-33993 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-4.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 21" width="512" height="607" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 24" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-4.jpg 512w, https://anonyviet.com/wp-content/uploads/2021/09/burp-4-253x300.jpg 253w" sizes="(max-width: 512px) 100vw, 512px"/></p>
<p>Set up the proxy as follows:</p>
<ul>
<li><strong>Manual proxy configuration</strong></li>
<li>HTTP Proxy: <strong>127.0.0.1</strong></li>
<li>Port: <strong>8080</strong></li>
<li>Tick <strong>Use this proxy for all protocols</strong></li>
</ul>
<p>Then press <strong>OK</strong>.</p>
<p>Now all browser traffic will go through Burp.</p>
<h2 id="ftoc-kiem-tra-proxy-listener-cua-burp" class="ftwp-heading">Check out Burp&#8217;s Proxy Listener</h2>
<p>Open Burp Suite:</p>
<p><img decoding="async" class="size-full wp-image-33994 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-5.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 22" width="612" height="321" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 25" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-5.jpg 612w, https://anonyviet.com/wp-content/uploads/2021/09/burp-5-300x157.jpg 300w" sizes="(max-width: 612px) 100vw, 612px"/></p>
<p>Make sure the Proxy Listener is:</p>
<ul>
<li>Host: <strong>127.0.0.1</strong></li>
<li>Port: <strong>8080</strong></li>
<li>Status: <strong>Running</strong></li>
</ul>
<h2 id="ftoc-test-chan-luu-luong-http" class="ftwp-heading">Test blocking HTTP traffic</h2>
<p>Access the simple HTTP page:</p>
<p><strong>http://neverssl.com</strong></p>
<p>Burp will block the request and display it in the tab <strong>Intercept</strong>.</p>
<p><img decoding="async" class="size-full wp-image-33995 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-6.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 23" width="572" height="252" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 26" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-6.jpg 572w, https://anonyviet.com/wp-content/uploads/2021/09/burp-6-300x132.jpg 300w" sizes="(max-width: 572px) 100vw, 572px"/></p>
<p>You can:</p>
<ul>
<li>See header</li>
<li>Edit parameters</li>
<li>Forward requests</li>
<li>Drop requests</li>
</ul>
<h2 id="ftoc-tai-sao-https-bi-loi-tls" class="ftwp-heading">Why does HTTPS fail TLS?</h2>
<p>When accessing an HTTPS site like:</p>
<p><strong>https://google.com</strong></p>
<p>You will see a TLS error.</p>
<p><img decoding="async" class="size-full wp-image-33996 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-7.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 24" width="657" height="243" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 27" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-7.jpg 657w, https://anonyviet.com/wp-content/uploads/2021/09/burp-7-300x111.jpg 300w" sizes="(max-width: 657px) 100vw, 657px"/></p>
<p>Reason:</p>
<ul>
<li>HTTPS encrypts data using TLS</li>
<li>Burp is in the middle (MITM)</li>
<li>The browser does not trust Burp&#8217;s certificate</li>
</ul>
<p>Therefore we need to install Burp&#8217;s CA certificate.</p>
<h2 id="ftoc-buoc-3-cai-chung-chi-burp-ca-de-chan-https" class="ftwp-heading">Step 3: Install Burp CA certificate to block HTTPS</h2>
<p>Open a browser and access:</p>
<p><strong>http://burp/</strong></p>
<p>Press <strong>CA Certificate</strong>.</p>
<p><img decoding="async" class="size-full wp-image-33997 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-8.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 25" width="1428" height="329" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 28" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-8.jpg 1428w, https://anonyviet.com/wp-content/uploads/2021/09/burp-8-300x69.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/burp-8-1024x236.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/burp-8-768x177.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/burp-8-750x173.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/burp-8-1140x263.jpg 1140w" sizes="(max-width: 1428px) 100vw, 1428px"/></p>
<p>Save the certificate file.</p>
<p>Next open:</p>
<p><strong>about:preferences</strong></p>
<p>Search <strong>Certificates</strong>.</p>
<p><img decoding="async" class="size-full wp-image-33998 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/burp-9.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 26" width="697" height="248" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 29" srcset="https://anonyviet.com/wp-content/uploads/2021/09/burp-9.jpg 697w, https://anonyviet.com/wp-content/uploads/2021/09/burp-9-300x107.jpg 300w" sizes="(max-width: 697px) 100vw, 697px"/></p>
<p>Select:</p>
<ul>
<li>View Certificates</li>
<li>Authorities</li>
<li>Import</li>
</ul>
<p>Select the Burp certificate file you just downloaded.</p>
<p><img decoding="async" class="size-full wp-image-33999 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/nurp-10.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 27" width="648" height="344" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 30" srcset="https://anonyviet.com/wp-content/uploads/2021/09/nurp-10.jpg 648w, https://anonyviet.com/wp-content/uploads/2021/09/nurp-10-300x159.jpg 300w" sizes="(max-width: 648px) 100vw, 648px"/></p>
<p>Tick ​​both options:</p>
<ul>
<li>Trust this CA to identify websites</li>
<li>Trust this CA to identify email users</li>
</ul>
<p>Press <strong>OK</strong>.</p>
<p>You can now block HTTPS without TLS errors.</p>
<h2 id="ftoc-cach-burp-suite-chan-request" class="ftwp-heading">How Burp Suite blocks requests</h2>
<p>Open:</p>
<p><strong>Proxy → Intercept</strong></p>
<p><img decoding="async" class="size-full wp-image-34000 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/new-b-1.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 28" width="1440" height="810" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 31" srcset="https://anonyviet.com/wp-content/uploads/2021/09/new-b-1.jpg 1440w, https://anonyviet.com/wp-content/uploads/2021/09/new-b-1-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/new-b-1-1024x576.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/new-b-1-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/new-b-1-750x422.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/new-b-1-1140x641.jpg 1140w" sizes="(max-width: 1440px) 100vw, 1440px"/></p>
<p>When turned on <strong>Intercept is ON</strong>:</p>
<ul>
<li>Request stops at Burp</li>
<li>You can edit the data</li>
<li>Then press <strong>Forward</strong></li>
</ul>
<p>For example, when logging into a website:</p>
<p><img decoding="async" class="size-full wp-image-34001 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 29" width="1440" height="810" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 32" srcset="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2.jpg 1440w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2-1024x576.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2-750x422.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-2-1140x641.jpg 1140w" sizes="(max-width: 1440px) 100vw, 1440px"/></p>
<p>You will see:</p>
<ul>
<li>HTTP headers</li>
<li>Cookies</li>
<li>POST data</li>
<li>Tokens</li>
</ul>
<h3 id="ftoc-chinh-sua-tham-so-request" class="ftwp-heading">Edit request parameters</h3>
<p>Switch tabs <strong>Params</strong>.</p>
<p><img decoding="async" class="size-full wp-image-34002 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 30" width="1440" height="810" title="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 33" srcset="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3.jpg 1440w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3-1024x576.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3-750x422.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-3-1140x641.jpg 1140w" sizes="(max-width: 1440px) 100vw, 1440px"/></p>
<p>Here you can:</p>
<ul>
<li>Edit value</li>
<li>Add parameters</li>
<li>Delete parameters</li>
</ul>
<p>This is how the pentester checks the server&#8217;s logic.</p>
<h2 id="ftoc-xem-toan-bo-lich-su-request" class="ftwp-heading">View full request history</h2>
<p>To see all requests:</p>
<p><strong>Proxy → HTTP History</strong></p>
<p><img decoding="async" class="size-full wp-image-34003 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5.jpg" alt="How to intercept traffic with Burp Suite to analyze HTTP/HTTPS 31" width="1440" height="810" title="How to intercept traffic using Burp Suite to analyze HTTP/HTTPS 34" srcset="https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5.jpg 1440w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5-300x169.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5-1024x576.jpg 1024w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5-768x432.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5-750x422.jpg 750w, https://anonyviet.com/wp-content/uploads/2021/09/new-burp-5-1140x641.jpg 1140w" sizes="(max-width: 1440px) 100vw, 1440px"/></p>
<p>You will see:</p>
<ul>
<li>List of requests</li>
<li>Status code</li>
<li>Domain</li>
<li>Method (GET/POST)</li>
</ul>
<p>Very useful when analyzing APIs or debugging web apps.</p>
<h2 id="ftoc-use-case-thuc-te-tai-viet-nam" class="ftwp-heading">Actual use-case in Vietnam</h2>
<p>Burp Suite is often used to:</p>
<ul>
<li>Analyze mobile app API</li>
<li>Debug website requests</li>
<li>Reverse engineer web service</li>
<li>Web security testing</li>
</ul>
<p>Many classmates <strong>Bug Bounty</strong> or <strong>Web Pentest</strong> all start with Burp.</p>
<p>If you are new to web security, you should combine it with a practice platform such as:</p>
<ul>
<li>TryHackMe</li>
<li>PortSwigger Web Security Academy</li>
</ul>
<h2 id="ftoc-loi-thuong-gap-khi-dung-burp-suite" class="ftwp-heading">Common errors when using Burp Suite</h2>
<h3 id="ftoc-1-khong-chan-duoc-request" class="ftwp-heading">1. Cannot block requests</h3>
<p>The cause is usually due to:</p>
<ul>
<li>Proxy is not configured correctly</li>
<li>Wrong port</li>
<li>Listener is not running</li>
</ul>
<h3 id="ftoc-2-https-bi-loi-tls" class="ftwp-heading">2. HTTPS fails TLS</h3>
<p>The Burp CA certificate has not been installed in the browser.</p>
<h3 id="ftoc-3-website-khong-tai" class="ftwp-heading">3. Website does not load</h3>
<p>Because Intercept is on but you have not forwarded the request yet.</p>
<h2 id="ftoc-faq-cau-hoi-thuong-gap" class="ftwp-heading">FAQ – Frequently asked questions</h2>
<h3 id="ftoc-burp-suite-co-mien-phi-khong" class="ftwp-heading">Is Burp Suite free?</h3>
<p>Have. Burp Suite Community Edition is free but some advanced features are only available in the Professional version.</p>
<h3 id="ftoc-burp-suite-co-dung-de-hack-khong" class="ftwp-heading">Is Burp Suite used for hacking?</h3>
<p>Burp Suite is a legitimate security testing tool. It is used by pentesters and security experts to detect vulnerabilities.</p>
<h3 id="ftoc-co-can-java-de-chay-burp-suite-khong" class="ftwp-heading">Is Java needed to run Burp Suite?</h3>
<p>New versions have integrated runtime, but some older versions still require Java.</p>
<h3 id="ftoc-nen-dung-trinh-duyet-nao-voi-burp" class="ftwp-heading">Which browser should I use with Burp?</h3>
<p>Firefox is often used because it is easy to configure proxies and certificates.</p>
<h2 id="ftoc-checklist-thiet-lap-burp-suite" class="ftwp-heading">Burp Suite setup checklist</h2>
<ul>
<li>Install Burp Suite Community</li>
<li>Proxy configuration 127.0.0.1:8080</li>
<li>Check Proxy Listener</li>
<li>Download Burp CA certificate</li>
<li>Import into Firefox</li>
<li>Turn on Intercept</li>
<li>Analyze request/response</li>
</ul>
<h2 id="ftoc-ket-luan" class="ftwp-heading">Conclude</h2>
<p><strong>Burp Suite</strong> is an extremely important tool in the field <strong>Web Security</strong>. Knowing how to intercept and analyze HTTP/HTTPS traffic helps you understand how web applications work and detect security issues.</p>
<p>If you are studying <strong>Pentest</strong>, <strong>Bug Bounty</strong> or API analysis, mastery of Burp Suite is an almost mandatory skill.</p>
<p>In the next articles, AnonyViet will provide further instructions on:</p>
<ul>
<li>Repeater</li>
<li>Intruder</li>
<li>Burp automation</li>
<li>Exploit real web vulnerabilities</li>
</ul>
<h2 id="ftoc-nguon-tham-khao" class="ftwp-heading">Reference source</h2>
<ul>
<li>PortSwigger Web Security Academy</li>
<li>TryHackMe</li>
<li>Burp Suite Official Document</li>
</ul>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-intercept-traffic-using-burp-suite-to-analyze-http-https/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Latest Active Burp Suite Pro 2024 + BugBounty Pro guide</title>
		<link>https://en.anonyviet.com/latest-active-burp-suite-pro-2024-bugbounty-pro-guide/</link>
					<comments>https://en.anonyviet.com/latest-active-burp-suite-pro-2024-bugbounty-pro-guide/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Mon, 04 Mar 2024 14:41:36 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Active]]></category>
		<category><![CDATA[BugBounty]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[latest]]></category>
		<category><![CDATA[Pro]]></category>
		<category><![CDATA[Suite]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=14834</guid>

					<description><![CDATA[Many of you who work on web servers or work in the security field have probably heard of a software that helps us check Web security called Burp Suite, right? Today I will guide you through the simplest Active Burp Suite Pro that ensures no malicious code. Join the channel Telegram belong to AnonyViet 👉 [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p><strong>Many of you who work on web servers or work in the security field have probably heard of a software that helps us check Web security called Burp Suite, right?  Today I will guide you through the simplest Active Burp Suite Pro that ensures no malicious code.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> belong to <span style="color: #008080;">AnonyViet</span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietoffical" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-burp-suite-la-gi" class="ftwp-heading">What is Burp Suite?</h2>
<p>Burp Suite is known as a software that integrates features in testing the security of web applications.  These features will test and evaluate the security level of elements of your website or today&#39;s modern websites.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2021%2F10%2Factive-burpsuite-pro-1.jpg" class="local-link" rel="noopener"><img post-id="1552" fifu-featured="1" loading="lazy" decoding="async" class="aligncenter size-full wp-image-35665" src="https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1.jpg" alt="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro" width="583" height="342" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 16" srcset="https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1.jpg 583w, https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1-300x176.jpg 300w" sizes="auto, (max-width: 583px) 100vw, 583px"/></a></p>
<p>With Burp Suite, you can use it to evaluate the following security criteria: Conduct authentication mechanism checks (Authentication), check user version issues (Version) or list and evaluate evaluate the input parameters of the web application (Input).</p>
<p>Burp Suite not only supports the manual security assessment process, but also provides functions that allow scanning for SSL security vulnerabilities and a number of other vulnerabilities.  The two versions of Burp Suite distributed by PortSwigger Ltd are Burp Suite Free and Burp Suite Pro (also known as Burp Pro).  Although the free version will have limited features, with the paid version you can exploit the full capabilities of Burp Suite at an affordable price.</p>
<p>AnonyViet has many quite detailed articles about <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftag%2Fburp-suite%2F" class="local-link" rel="noopener">Burp Suite</a>you should read it all to understand how to use it.</p>
<h2 id="ftoc-tai-sao-nen-dung-burp-suite" class="ftwp-heading">Why should you use Burp Suite?</h2>
<ul>
<li><strong>All free</strong>: Although there are two versions that exist in parallel, the Burp Suite Free version and the Burp Suite Pro version, the free version gives us most of the necessary functions such as proxy server, web spider, intruder and repeater.</li>
<li><strong>Convenient</strong>: Instead of having to turn on many tools at once, Burp Suite will help you and support you in security testing</li>
<li><strong>Easy to use</strong>: With the development of Java, Burp Suite has a simple and neat user interface.</li>
</ul>
<h2 id="ftoc-so-sanh-burp-free-va-burp-pro" class="ftwp-heading">Compare Burp Free and Burp Pro</h2>
<h3 id="ftoc-burp-free" class="ftwp-heading">Burp Free</h3>
<ul>
<li>Inspect and modify traffic between browser and Target using Proxy</li>
<li>Target information collection and functionality</li>
<li>Resend each package individually</li>
<li>Many utilities analyze and decode data</li>
</ul>
<h3 id="ftoc-burp-pro" class="ftwp-heading">Burp Pro</h3>
<ul>
<li>Has all the functions of Burp Free</li>
<li>Automatically scan for security vulnerabilities</li>
<li>Exploit complex security vulnerabilities</li>
<li>Allow Save process and continue</li>
<li>Analyze web data</li>
<li>Receive regular updates and security patches</li>
</ul>
<h2 id="ftoc-huong-dan-active-burp-suite-pro-2024" class="ftwp-heading">Active Burp Suite Pro 2024 Instructions</h2>
<p>Currently the latest version is Burp Suite 2022.3.9, I have packaged into a compressed file all the tools to Active License for Burp Suite Pro in the link below, you need to follow the steps below:</p>
<p style="text-align: center;"><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.fshare.vn%2Ffile%2F5THLCJINFX7U" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"><span style="font-size: 18pt; color: #ff0000;"><strong>Download Burp Suite Pro 2024</strong></span></a></p>
<p style="text-align: center;">(Includes Burp Suite Pro installation file from PortSwigger Ltd)</p>
<p><span style="text-decoration: underline;"><strong>Note that if you want to download it yourself, you can download it here:</strong></span></p>
<ul>
<li>You need to install it <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.oracle.com%2Fjava%2Ftechnologies%2Fdownloads%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">JDK</a> (Java Developer Kit) and <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fjavadl.oracle.com%2Fwebapps%2Fdownload%2FAutoDL%3FBundleId%3D244068_89d678f2be164786b292527658ca1605" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Java</a> to be able to install Burp Suite Pro.  It is mandatory to have these two things, otherwise the active file will not run!</li>
<li>Download files <strong>Burp Suite Pro</strong> latest edition <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fportswigger.net%2Fburp%2Freleases%2Fdownload%3Fproduct%3Dpro" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">here</a>.</li>
</ul>
<p><strong>Latest Active Burp Suite:</strong></p>
<ol>
<li>Go to the Java Setup folder, install 2 files inside.</li>
<li>Open the burploader.jar file to Get Key</li>
<li>Open the burp.bat file to run Burp Suite</li>
</ol>
<p><strong>See detailed image below:</strong></p>
<p><strong>Step 1:</strong> You unzip the Zip file just arrived into the folder</p>
<p><strong>Step 2</strong>: Run file <code>burp.bat</code>.  After running, Burp Suite&#39;s setup will appear</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33759 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/a-23.jpg" alt="Run Burp.bat" width="842" height="442" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 17" srcset="https://anonyviet.com/wp-content/uploads/2021/09/a-23.jpg 842w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-768x403.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-750x394.jpg 750w" sizes="auto, (max-width: 842px) 100vw, 842px"/></p>
<p><strong>Step 3</strong>: Click Accept</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33760 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/c.jpg" alt="Accept Burp Suite terms" width="341" height="319" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 18" srcset="https://anonyviet.com/wp-content/uploads/2021/09/c.jpg 341w, https://anonyviet.com/wp-content/uploads/2021/09/c-300x281.jpg 300w" sizes="auto, (max-width: 341px) 100vw, 341px"/></p>
<p><strong>Step 4</strong>: Run File <code>burploader.jar</code></p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33761 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/b.jpg" alt="Run File Keygen.jar" width="845" height="443" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 19" srcset="https://anonyviet.com/wp-content/uploads/2021/09/b.jpg 845w, https://anonyviet.com/wp-content/uploads/2021/09/b-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/b-768x403.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/b-750x393.jpg 750w" sizes="auto, (max-width: 845px) 100vw, 845px"/></p>
<p><strong>Step 5</strong>: Change the “License to <any name>” section.  I will leave the License to Anonymousviet</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33762 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/e.jpg" alt="Rename License" width="602" height="336" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 20" srcset="https://anonyviet.com/wp-content/uploads/2021/09/e.jpg 602w, https://anonyviet.com/wp-content/uploads/2021/09/e-300x167.jpg 300w" sizes="auto, (max-width: 602px) 100vw, 602px"/></p>
<p><strong>Step 6</strong>: Copy the License section to the setup section and click Next</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33763 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/f.jpg" alt="Copy License to Setup File" width="956" height="327" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 21" srcset="https://anonyviet.com/wp-content/uploads/2021/09/f.jpg 956w, https://anonyviet.com/wp-content/uploads/2021/09/f-300x103.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/f-768x263.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/f-750x257.jpg 750w" sizes="auto, (max-width: 956px) 100vw, 956px"/></p>
<p><strong>Step 7</strong>: You choose Manual Activation</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33764 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/g.jpg" alt="Manual Activation" width="342" height="320" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 22" srcset="https://anonyviet.com/wp-content/uploads/2021/09/g.jpg 342w, https://anonyviet.com/wp-content/uploads/2021/09/g-300x281.jpg 300w" sizes="auto, (max-width: 342px) 100vw, 342px"/></p>
<p><strong>Step 8</strong>: You choose Copy Request and paste it into Activation Request</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33765 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/h.jpg" alt="Copy Request to" width="949" height="329" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 23" srcset="https://anonyviet.com/wp-content/uploads/2021/09/h.jpg 949w, https://anonyviet.com/wp-content/uploads/2021/09/h-300x104.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/h-768x266.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/h-750x260.jpg 750w" sizes="auto, (max-width: 949px) 100vw, 949px"/></p>
<p><strong>Step 9</strong>: Copy the Activation Response section and Paste into Setup and click next</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33766 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/i.jpg" alt="Copy Respond to setup" width="959" height="330" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 24" srcset="https://anonyviet.com/wp-content/uploads/2021/09/i.jpg 959w, https://anonyviet.com/wp-content/uploads/2021/09/i-300x103.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/i-768x264.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/i-750x258.jpg 750w" sizes="auto, (max-width: 959px) 100vw, 959px"/></p>
<p><strong>Note</strong>: If it reports <strong>Activation Failed</strong> then try again from <strong>step 8</strong></p>
<p><strong>Step 10</strong>: Click Finish</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33767 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/k.jpg" alt="Select Finish" width="335" height="316" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 25" srcset="https://anonyviet.com/wp-content/uploads/2021/09/k.jpg 335w, https://anonyviet.com/wp-content/uploads/2021/09/k-300x283.jpg 300w" sizes="auto, (max-width: 335px) 100vw, 335px"/></p>
<p><strong>Step 11</strong>: Run file <code>burp.vbs</code> to open Burp Suite Pro.</p>
<p>Remember to right click on the file<code> burp.vbs</code> to correct the file path <code>burp.bat</code>.</p>
<p><img loading="lazy" decoding="async" class="size-full wp-image-33768 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/l.jpg" alt="Run File Burp.VBS to start burp" width="842" height="440" title="Latest Active Burp Suite Pro 2024 + BugBounty Pro Guide 26" srcset="https://anonyviet.com/wp-content/uploads/2021/09/l.jpg 842w, https://anonyviet.com/wp-content/uploads/2021/09/l-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/l-768x401.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/l-750x392.jpg 750w" sizes="auto, (max-width: 842px) 100vw, 842px"/></p>
<h2 id="ftoc-cach-fix-loi-to-run-burp-suite-using-java-17-please-supply-the-following-jvm-argument" class="ftwp-heading">How to fix error to run burp suite using java 17+ please provide the following jvm arguments</h2>
<p>For new versions of Burp Suite, even though Java 17 and Java 18 are installed, they still get the error &#8220;run burp suite using java 17+ please provide the following jvm arguments&#8221;, do the following:</p>
<p><strong>Step 1:</strong> Open the folder containing the Burpsite file and File Loader</p>
<p><strong>Step 2: </strong> Open CMD in the above directory and type the command:</p>
<p>Change <code>burploader.jar</code> and <code>burpsuite_pro_v2022.3.9.jar</code> matches the file name in the directory</p>
<p><code>java -noverify -javaagent:burploader.jar -jar --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.desktop/javax.swing=ALL-UNNAMED burpsuite_pro_v2022.3.9.jar</code></p>
<p>Or create files <code>start.bat</code> with the content below, then run the file <code>start.bat</code> is to be.</p>
<p><code>java -noverify -javaagent:burploader.jar -jar --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.desktop/javax.swing=ALL-UNNAMED burpsuite_pro_v2022.3.9.jar</code></p>
<p><strong>So I have completed instructions on how to setup and activate Burp Suite Pro in the simplest way.  Does anyone else&#39;s installation fail continuously?🤣 Please leave a comment below so I can answer you as well as support you!  Wish everyone have a good day <3</strong></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;56982&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;H\u01b0\u1edbng d\u1eabn Active Burp Suite Pro 2024 + BugBounty Pro m\u1edbi nh\u1ea5t&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>  The article scored: 5/5 &#8211; (100 votes)</p>
</div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/latest-active-burp-suite-pro-2024-bugbounty-pro-guide/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/09/burpsuite-twittercard.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Web Pentest &#8211; Lesson 1: An overview of Burp Suite</title>
		<link>https://en.anonyviet.com/web-pentest-lesson-1-an-overview-of-burp-suite/</link>
					<comments>https://en.anonyviet.com/web-pentest-lesson-1-an-overview-of-burp-suite/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Wed, 25 Jan 2023 06:57:17 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[Lesson]]></category>
		<category><![CDATA[overview]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Suite]]></category>
		<category><![CDATA[web]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=2666</guid>

					<description><![CDATA[Nowadays, creating and developing a website is not difficult for everyone. Creating a website can be of great help to everyone and especially in the current 4.0 era. In addition, the Covid-19 pandemic has made our tendency to go online on websites. But have you ever wondered if the website you build is safe enough [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>Nowadays, creating and developing a website is not difficult for everyone.  Creating a website can be of great help to everyone and especially in the current 4.0 era.  In addition, the Covid-19 pandemic has made our tendency to go online on websites.  But have you ever wondered if the website you build is safe enough for you and the customers accessing the system?  What if a bad guy attacks your Website?</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p>So today <strong>Anonyviet</strong> will bring you a series on the security of your Website system.  You will be playing the role of a bad guy and attack on your website (Penttest) and from there will find out the error on the system and how to fix it.</p>
<h2 id="ftoc-tong-quan-ve-phan-mem-ho-tro-pentest-burpsuite" class="ftwp-heading">Pentest Burpsuite Support Software Overview</h2>
<p><strong>Installation Requirements: </strong></p>
<p><strong>About BurpSuite</strong></p>
<p>Burpsuite currently has many different versions.  Each version has quite different features and interfaces.  In this article, Anonyviet will introduce this Burpsuite 2021.4.3 version.</p>
<p>After installation, you open Burp Suite and you will have the same interface as below.</p>
<p><img decoding="async" class="alignnone wp-image-28381 size-full" src="https://anonyviet.com/wp-content/uploads/2021/07/a.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 13" width="2000" height="1566" srcset="https://anonyviet.com/wp-content/uploads/2021/07/a.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/a-300x235.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/a-1024x802.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/a-768x601.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/a-1536x1203.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/a-750x587.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/a-1140x893.png 1140w" sizes="(max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 15"/></p>
<h2 id="ftoc-cach-su-dung-burp-suite" class="ftwp-heading">How to use Burp Suite</h2>
<p>In the Dashboard interface, there will be information about the Tasks running on the website that need to be pentested.  The EventLog below shows the detected vulnerabilities.  The information in the EventLog frame is quite important, there are many errors related to the certificate, the connection error is also displayed here.  Makes it easier to spot and solve it faster.</p>
<p>Next is the Target section</p>
<p><img decoding="async" loading="lazy" class="wp-image-28383 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/b.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 14" width="2362" height="1850" srcset="https://anonyviet.com/wp-content/uploads/2021/07/b.png 2362w, https://anonyviet.com/wp-content/uploads/2021/07/b-300x235.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/b-1024x802.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/b-768x602.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/b-1536x1203.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/b-2048x1604.png 2048w, https://anonyviet.com/wp-content/uploads/2021/07/b-750x587.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/b-1140x893.png 1140w" sizes="auto, (max-width: 2362px) 100vw, 2362px" title="Web Pentest - Lesson 1: An overview of Burp Suite 16"/></p>
<p>In Target, there will be information about the subsites of that website that are allowed to access, requests can be made on these sites, you can press the > button in each site, to view it in a tree, there will be more intuitive view of the target.</p>
<p>Also in the Target, can serve to filter requests more quickly than in the Scope subtab.</p>
<p>Next is the Proxy tab interface, this is an extremely important part in Burp Suite.  The HTTP history tab will save the history of requests made during real-time manipulation right on the application or Website.  You can directly view the request, response and edit it.</p>
<p>From the Proxy tab, you can select a request and send this request to other tools in Burp Suite that support such as Repeater, Intruder, Comparer, &#8230;</p>
<p>In the latest version that I introduce, Burpsuite has integrated the Chromium browser, which is very convenient and saves you from having to manually configure it on other browsers.</p>
<p>To open Chromium, click Open Browser like the image below.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28384 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/c.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 15" width="1726" height="686" srcset="https://anonyviet.com/wp-content/uploads/2021/07/c.png 1726w, https://anonyviet.com/wp-content/uploads/2021/07/c-300x119.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/c-1024x407.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/c-768x305.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/c-1536x610.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/c-750x298.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/c-1140x453.png 1140w" sizes="auto, (max-width: 1726px) 100vw, 1726px" title="Web Pentest - Lesson 1: An overview of Burp Suite 17"/></p>
</p>
<p>When the Chromium browser is launched, you go to any website, <strong>Anonyviet</strong>.Com for example, and see the recorded requests in the HTTP Proxy tab.  If not, your Intercept is off.  Click to turn it on.</p>
<p>The next tab is Intruder.  Used a lot to BruteForce Username, Password, Directory or test IDOR…</p>
<p><img decoding="async" loading="lazy" class="wp-image-28385 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/d.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 16" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/d.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/d-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/d-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/d-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/d-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/d-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/d-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/d-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 18"/></p>
</p>
<p>Next to the Intruder tab, it is the Repeater, which is an indispensable component for every time we pentest.  Here, it allows us to edit any component of the request, from methods, headers, parameters, etc. After editing the request, you click Send to send the request to the server and receive the response.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28408 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 17" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-13-32-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 19"/></p>
</p>
<p>I say this is an indispensable ingredient, not just saying.  That&#8217;s because attacking a target requires us to send payloads in different locations.  The same is true of BurpSuite.</p>
<p>Changing the request itself like this allows us to try out all the payloads we have, look for reflected inputs in the response (when looking for XSS vulnerabilities), or see the results returned when we type the payload as SQL injection,…, and to do those tasks, Repeater is the best solution to do it.</p>
<p>This part is quite important, so I will go into detail in the next articles.  Remember to follow along.</p>
<p>Next is the Sequencer tab, which is used to analyze the complexity of the token generation algorithms in the website.  See if it&#8217;s easy to guess.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28409 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/e.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 18" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/e.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/e-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/e-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/e-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/e-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/e-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/e-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/e-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 20"/></p>
</p>
<p>Next is Tab Decoder used to encode or decode character types such as MD5, AES, BASE64 &#8230;</p>
<p><img decoding="async" loading="lazy" class="wp-image-28410 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 19" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/upload_2021-5-6_13-14-15-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 21"/></p>
</p>
<p>Tab Comparer, used to compare different requests and responses, sent by you through tabs such as proxy tabs or target tabs.  You can send by right-clicking the request and selecting send to comparer.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28411 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/p.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 20" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/p.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/p-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/p-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/p-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/p-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/p-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/p-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/p-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 22"/></p>
</p>
<p>The Logger tab, as the name suggests, will save all requests executed in the Burp Suite.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28412 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/u.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 21" width="2000" height="1417" srcset="https://anonyviet.com/wp-content/uploads/2021/07/u.png 2000w, https://anonyviet.com/wp-content/uploads/2021/07/u-300x213.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/u-1024x726.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/u-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/u-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/u-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/u-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/u-1140x808.png 1140w" sizes="auto, (max-width: 2000px) 100vw, 2000px" title="Web Pentest - Lesson 1: An overview of Burp Suite 23"/></p>
<p>The Extender tab is an interesting tab, it allows you to add new Burp existing extensions, or add extensions developed by yourself.  I will go into more detail in the next posts.</p>
<p><img decoding="async" loading="lazy" class="wp-image-28413 size-full aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/07/v.png" alt="Web Pentest - Lesson 1: An overview of Burp Suite 22" width="2612" height="1850" srcset="https://anonyviet.com/wp-content/uploads/2021/07/v.png 2612w, https://anonyviet.com/wp-content/uploads/2021/07/v-300x212.png 300w, https://anonyviet.com/wp-content/uploads/2021/07/v-1024x725.png 1024w, https://anonyviet.com/wp-content/uploads/2021/07/v-768x544.png 768w, https://anonyviet.com/wp-content/uploads/2021/07/v-1536x1088.png 1536w, https://anonyviet.com/wp-content/uploads/2021/07/v-2048x1451.png 2048w, https://anonyviet.com/wp-content/uploads/2021/07/v-120x86.png 120w, https://anonyviet.com/wp-content/uploads/2021/07/v-750x531.png 750w, https://anonyviet.com/wp-content/uploads/2021/07/v-1140x807.png 1140w" sizes="auto, (max-width: 2612px) 100vw, 2612px" title="Web Pentest - Lesson 1: An overview of Burp Suite 24"/></p>
</p>
<p>Here are some basics that you must be familiar with before the pentesting process begins.  You can learn more on your own, it will be very helpful for beginners.  In the next articles we will learn about Bruteforce techniques, collect information, etc. Hope you will watch and support.</p>
<p><strong>Summary Series : </strong></p>
<p style="text-align: right;"><strong>Good luck<br />TMQ.</strong></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;27482&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/web-pentest-lesson-1-an-overview-of-burp-suite/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/07/maxresdefault.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro</title>
		<link>https://en.anonyviet.com/guide-to-active-burp-suite-pro-2022-latest-bugbounty-pro/</link>
					<comments>https://en.anonyviet.com/guide-to-active-burp-suite-pro-2022-latest-bugbounty-pro/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Tue, 24 Jan 2023 07:03:47 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Active]]></category>
		<category><![CDATA[BugBounty]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[Guide]]></category>
		<category><![CDATA[latest]]></category>
		<category><![CDATA[Pro]]></category>
		<category><![CDATA[Suite]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=1552</guid>

					<description><![CDATA[Many of you who work as web servers or work in security, must have heard of a software that helps us check Web security called Burp Suite, right? Today I will guide Active Burp Suite Pro in the simplest way that ensures no malicious code. Join the channel Telegram of the AnonyViet 👉 Link 👈 [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<p><strong>Many of you who work as web servers or work in security, must have heard of a software that helps us check Web security called Burp Suite, right?  Today I will guide Active Burp Suite Pro in the simplest way that ensures no malicious code.</strong></p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<h2 id="ftoc-burp-suite-la-gi" class="ftwp-heading">What is Burp Suite?</h2>
<p>Burp Suite is known as a software that integrates features in testing the security of web applications.  These features will test and evaluate the security of the elements of your website or modern day web pages.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2021%2F10%2Factive-burpsuite-pro-1.jpg" rel="noopener" class="local-link"><img post-id="1552" fifu-featured="1" decoding="async" class="aligncenter size-full wp-image-35665" src="https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1.jpg" alt="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro" width="583" height="342" srcset="https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1.jpg 583w, https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1-300x176.jpg 300w" sizes="(max-width: 583px) 100vw, 583px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 16"/></a></p>
<p>With Burp Suite, you can use it to evaluate the following security criteria: Conduct authentication check (Authentication), check for user version (Version) issues or list and evaluate evaluate the input parameters of the web application (Input).</p>
<p>Burp Suite not only supports the manual security assessment process, but also provides functions that allow scanning for SSL vulnerabilities and a number of other vulnerabilities.  The two versions of Burp Suite distributed by PortSwigger Ltd are Burp Suite Free and Burp Suite Pro (also known as Burp Pro).  Although the free version will be limited in features, with the paid version, you can exploit the full capabilities of Burp Suite at an affordable price.</p>
<p>AnonyViet has had many detailed articles about <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Ftag%2Fburp-suite%2F" rel="noopener" class="local-link">Burp Suite</a>you should read it all to understand how to use it.</p>
<h2 id="ftoc-tai-sao-nen-dung-burp-suite" class="ftwp-heading">Why should you use Burp Suite?</h2>
<ul>
<li><strong>All free</strong>: Although there are 2 versions that exist in parallel, Burp Suite Free and Burp Suite Pro, but the free version has given us most of the necessary functions such as proxy server, web spider, intruder and repeater.</li>
<li><strong>Convenient</strong>: Instead of having to turn on many tools at once, Burp Suite will help you and assist you in security testing</li>
<li><strong>Easy to use</strong>: With the development of Java, Burp Suite has a clean and simple user interface.</li>
</ul>
<h2 id="ftoc-so-sanh-burp-free-va-burp-pro" class="ftwp-heading">Compare Burp Free and Burp Pro</h2>
<h3 id="ftoc-burp-free" class="ftwp-heading">Burp Free</h3>
<ul>
<li>Inspect and modify traffic between browser and Target using Proxy</li>
<li>Target&#8217;s Information Collection and Functions</li>
<li>Resend individual packages</li>
<li>Multiple data analysis and decoding utilities</li>
</ul>
<h3 id="ftoc-burp-pro" class="ftwp-heading">Burp Pro</h3>
<ul>
<li>Has all the functions of Burp Free</li>
<li>Automatically scan for security holes</li>
<li>Exploit complex security holes</li>
<li>Allow Save process and continue</li>
<li>Web data analytics</li>
<li>Get regular security updates and patches</li>
</ul>
<h2 id="ftoc-huong-dan-active-burp-suite-pro-2022" class="ftwp-heading">Guide to Active Burp Suite Pro 2022</h2>
<p>Currently the latest version is Burp Suite 2022.3.9, I have packaged it into a compressed file of all the tools to Active License for Burp Suite Pro in the link below, you need to follow the steps below:</p>
<p style="text-align: center;"><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.fshare.vn%2Ffile%2FVQSFJ6WQP5AO" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"><span style="font-size: 18pt; color: #ff0000;"><strong>Download Burp Suite Pro 2022</strong></span></a></p>
<p style="text-align: center;">(Included with Burp Suite Pro installation file from PortSwigger Ltd)</p>
<p><span style="text-decoration: underline;"><strong>Note if you want to download it yourself, you can download it here:</strong></span></p>
<ul>
<li>You need to install <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.oracle.com%2Fjava%2Ftechnologies%2Fdownloads%2F" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">JDK</a> (Java Deverloper Kit) and <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fjavadl.oracle.com%2Fwebapps%2Fdownload%2FAutoDL%3FBundleId%3D244068_89d678f2be164786b292527658ca1605" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Java</a> to be able to install Burp Suite Pro.  These 2 are required or the active file will not run!</li>
<li>Download files <strong>Burp Suite Pro</strong> latest edition <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fportswigger.net%2Fburp%2Freleases%2Fdownload%3Fproduct%3Dpro" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">here</a>.</li>
</ul>
<p><strong>Latest Active Burp Suite:</strong></p>
<ol>
<li>Go to the Java Setup folder, install 2 files inside it.</li>
<li>Open the file burploader.jar to Get Key</li>
<li>Open the file burp.bat to run Burp Suite</li>
</ol>
<p><strong>See picture below for details:</strong></p>
<p><strong>Step 1:</strong> You extract the zip file you just returned to the folder</p>
<p><strong>Step 2</strong>: Run file <code>burp.bat</code>.  After running, Burp Suite&#8217;s setup will appear</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33759 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/a-23.jpg" alt="Run Burp.bat" width="842" height="442" srcset="https://anonyviet.com/wp-content/uploads/2021/09/a-23.jpg 842w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-768x403.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/a-23-750x394.jpg 750w" sizes="auto, (max-width: 842px) 100vw, 842px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 17"/></p>
<p><strong>Step 3</strong>: Click Accept</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33760 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/c.jpg" alt="Accept terms Burp Suite" width="341" height="319" srcset="https://anonyviet.com/wp-content/uploads/2021/09/c.jpg 341w, https://anonyviet.com/wp-content/uploads/2021/09/c-300x281.jpg 300w" sizes="auto, (max-width: 341px) 100vw, 341px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 18"/></p>
<p><strong>Step 4</strong>: Run File <code>burploader.jar</code></p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33761 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/b.jpg" alt="Run File Keygen.jar" width="845" height="443" srcset="https://anonyviet.com/wp-content/uploads/2021/09/b.jpg 845w, https://anonyviet.com/wp-content/uploads/2021/09/b-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/b-768x403.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/b-750x393.jpg 750w" sizes="auto, (max-width: 845px) 100vw, 845px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 19"/></p>
<p><strong>Step 5</strong>: Change the “License to <any name>” section.  I will leave the License to Anonyviet</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33762 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/e.jpg" alt="Rename License" width="602" height="336" srcset="https://anonyviet.com/wp-content/uploads/2021/09/e.jpg 602w, https://anonyviet.com/wp-content/uploads/2021/09/e-300x167.jpg 300w" sizes="auto, (max-width: 602px) 100vw, 602px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 20"/></p>
<p><strong>Step 6</strong>: Copy the License section to the setup section and click Next</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33763 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/f.jpg" alt="Copy License to Setup File" width="956" height="327" srcset="https://anonyviet.com/wp-content/uploads/2021/09/f.jpg 956w, https://anonyviet.com/wp-content/uploads/2021/09/f-300x103.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/f-768x263.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/f-750x257.jpg 750w" sizes="auto, (max-width: 956px) 100vw, 956px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 21"/></p>
<p><strong>Step 7</strong>: You choose Manual Activation</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33764 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/g.jpg" alt="Manual Activation " width="342" height="320" srcset="https://anonyviet.com/wp-content/uploads/2021/09/g.jpg 342w, https://anonyviet.com/wp-content/uploads/2021/09/g-300x281.jpg 300w" sizes="auto, (max-width: 342px) 100vw, 342px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 22"/></p>
<p><strong>Step 8</strong>: You choose Copy Request and paste it into Activation Request</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33765 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/h.jpg" alt="Copy Request to" width="949" height="329" srcset="https://anonyviet.com/wp-content/uploads/2021/09/h.jpg 949w, https://anonyviet.com/wp-content/uploads/2021/09/h-300x104.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/h-768x266.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/h-750x260.jpg 750w" sizes="auto, (max-width: 949px) 100vw, 949px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 23"/></p>
<p><strong>Step 9</strong>: Copy the Activation Response and Paste it into Setup and click next</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33766 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/i.jpg" alt="Copy Respond to setup" width="959" height="330" srcset="https://anonyviet.com/wp-content/uploads/2021/09/i.jpg 959w, https://anonyviet.com/wp-content/uploads/2021/09/i-300x103.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/i-768x264.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/i-750x258.jpg 750w" sizes="auto, (max-width: 959px) 100vw, 959px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 24"/></p>
<p><strong>Note</strong>: If it says <strong>Activation Failed</strong> then try again from <strong>step 8</strong></p>
<p><strong>Step 10</strong>: Click Finish</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33767 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/k.jpg" alt="Select Finish" width="335" height="316" srcset="https://anonyviet.com/wp-content/uploads/2021/09/k.jpg 335w, https://anonyviet.com/wp-content/uploads/2021/09/k-300x283.jpg 300w" sizes="auto, (max-width: 335px) 100vw, 335px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 25"/></p>
<p><strong>Step 11</strong>: Run file <code>burp.vbs</code> to open Burp Suite Pro.</p>
<p>Remember to right click on the file<code> burp.vbs</code> to correct the path of the file <code>burp.bat</code>.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-33768 aligncenter" src="https://anonyviet.com/wp-content/uploads/2021/09/l.jpg" alt="Run File Burp.VBS to start burp" width="842" height="440" srcset="https://anonyviet.com/wp-content/uploads/2021/09/l.jpg 842w, https://anonyviet.com/wp-content/uploads/2021/09/l-300x157.jpg 300w, https://anonyviet.com/wp-content/uploads/2021/09/l-768x401.jpg 768w, https://anonyviet.com/wp-content/uploads/2021/09/l-750x392.jpg 750w" sizes="auto, (max-width: 842px) 100vw, 842px" title="Guide to Active Burp Suite Pro 2022 + Latest BugBounty Pro 26"/></p>
<h2 id="ftoc-cach-fix-loi-to-run-burp-suite-using-java-17-please-supply-the-following-jvm-argument" class="ftwp-heading">How to fix error to run burp suite using java 17+ please supply the following jvm argument</h2>
<p>For new versions of Burp Suite, even though Java 17 and Java 18 are installed, but still get the error &#8220;run burp suite using java 17+ please supply the following jvm argument&#8221;, you do the following:</p>
<p><strong>Step 1:</strong> Open the folder with files Burpsite and File Loader</p>
<p><strong>Step 2: </strong> Open CMD in the above directory and type the command:</p>
<p>Change <code>burploader.jar</code> and <code>burpsuite_pro_v2022.3.9.jar</code> match the file name in the directory</p>
<p><code>java -noverify -javaagent:burploader.jar -jar --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.desktop/javax.swing=ALL-UNNAMED burpsuite_pro_v2022.3.9.jar</code></p>
<p>Or create a file <code>start.bat</code> with the content below, then run the file <code>start.bat</code> is to be.</p>
<p><code>java -noverify -javaagent:burploader.jar -jar --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.desktop/javax.swing=ALL-UNNAMED burpsuite_pro_v2022.3.9.jar</code></p>
<p><strong>So I have finished guiding how to set up and activate Burp Suite Pro in the simplest way.  Has anyone finished installing Fail continuously?🤣 Please leave a comment below so I can answer for you as well as support you!  Have a nice day everyone <3</strong></p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;33670&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/guide-to-active-burp-suite-pro-2022-latest-bugbounty-pro/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2021/10/active-burpsuite-pro-1.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>Download Burp Suite 2022.11 Pro Full Key &#8211; How to Active Copyright</title>
		<link>https://en.anonyviet.com/download-burp-suite-2022-11-pro-full-key-how-to-active-copyright/</link>
					<comments>https://en.anonyviet.com/download-burp-suite-2022-11-pro-full-key-how-to-active-copyright/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Thu, 12 Jan 2023 21:25:15 +0000</pubDate>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Active]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[Copyright]]></category>
		<category><![CDATA[Download]]></category>
		<category><![CDATA[Full]]></category>
		<category><![CDATA[Key]]></category>
		<category><![CDATA[Pro]]></category>
		<category><![CDATA[Suite]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=1170</guid>

					<description><![CDATA[What is Burp Suite? Burp Suite 2022.11 Pro Full (abbreviated as Burp) is a well known and popular integration tool, used to perform security penetration tests for web applications. Actually it is more commonly used for activities Website hacking. The software is written in Java, developed by PortSwigger from UK. Join the channel Telegram of [&#8230;]]]></description>
										<content:encoded><![CDATA[<p></p>
<div id="ftwp-postcontent">
<h2 id="ftoc-burp-suite-la-gi" class="ftwp-heading">What is Burp Suite?</h2>
<p><strong>Burp Suite 2022.11 Pro Full</strong> (abbreviated as Burp) is a well known and popular integration tool, used to perform security penetration tests for web applications.  Actually it is more commonly used for activities <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2F%3Fs%3Dhack%2Bwebsite" rel="noopener" class="local-link">Website hacking</a>.  The software is written in Java, developed by PortSwigger from UK.</p>
<div class="code-block code-block-16" style="margin: 8px 0; clear: both;">
<div align="center">
<table class=" aligncenter" style="background-color: #c0c0c0; border-collapse: collapse; width: 59.9985%;">
<tbody>
<tr>
<td style="width: 100%; text-align: center;"><span style="font-size: 12pt;"><strong>Join the channel <span style="color: #0000ff;">Telegram</span> of the <span style="color: #008080;">AnonyViet </span> 👉 <span style="text-decoration: underline;"><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Ft.me%2Fanonyvietchat" class="local-link" rel="noopener">Link</a></span>  👈</strong></span></td>
</tr>
</tbody>
</table>
</div>
</div>
<p><strong>Burp Suite 2022.11 Pro Full Key</strong> provides you with a simple means of performing Website security testing.  It gives you full control, allowing you to combine advanced manual techniques in coordination with many other testing tools for the testing process.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2FBurp-Suite-Pro-Full.jpg" rel="noopener" class="local-link"><img post-id="1170" fifu-featured="1" decoding="async" class="aligncenter wp-image-16212 size-full" src="https://anonyviet.com/wp-content/uploads/2019/11/Burp-Suite-Pro-Full.jpg" alt="Download Burp Suite 2022.11 Pro Full Key &#8211; How to Active Copyright" title="Download Burp Suite 2022.11 Pro Full Key &#8211; How to Active Copyright" width="750" height="525" srcset="https://anonyviet.com/wp-content/uploads/2019/11/Burp-Suite-Pro-Full.jpg 750w, https://anonyviet.com/wp-content/uploads/2019/11/Burp-Suite-Pro-Full-300x210.jpg 300w" sizes="(max-width: 750px) 100vw, 750px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 11"/></a></p>
<p><strong>Burp Suite 2012.12 Crack</strong> includes a number of tools for network attacks and many interfaces have been designed for these tools, to facilitate and speed up the application attack process.  The tool helps to analyze the information of: HTTP messages, persistence, certification, proxy, log, alert, etc. Its diverse functions can help us to perform various tasks, including blocking and editing. modify network requests, scan web applications for vulnerabilities, crack logins with brute force, sessions, tokens and other random checks.</p>
<p>In short, is one of the best tools for website security testing.  Burp Suite is a bit difficult to use, especially with its complicated parameters.  But once you understand how to use it, this will be a powerful tool for Hackers.</p>
<h3 id="ftoc-cac-tinh-nang" class="ftwp-heading">Functions</h3>
<table style="border-collapse: collapse; width: 99.806%;">
<tbody>
<tr>
<td style="width: 14.8%;">Feature</td>
<td style="width: 85.0667%;">Description</td>
</tr>
<tr>
<td style="width: 14.8%;">HTTP Proxy</td>
<td style="width: 85.0667%;"> Acts as a web proxy server and sits in the middle between the browser and the destination web server.  Enables interception, inspection and modification of data traffic passing from two directions.</td>
</tr>
<tr>
<td style="width: 14.8%;">Scanner</td>
<td style="width: 85.0667%;">A web application security scanner.  Used to perform vulnerability scanning of web applications.</td>
</tr>
<tr>
<td style="width: 14.8%;">Intruder</td>
<td style="width: 85.0667%;">This tool can perform automated attacks on web applications.  The tool provides a configurable algorithm that can make malicious HTTP requests.  The intrusion tool can test and detect SQL Injections, Cross Site Scripting, parameter manipulation, and brute-force vulnerabilities.</td>
</tr>
<tr>
<td style="width: 14.8%;">Spider</td>
<td style="width: 85.0667%;">Tool to automatically crawl web applications.  It can be used in conjunction with manual mapping techniques to speed up the app functionality and content mapping.</td>
</tr>
<tr>
<td style="width: 14.8%;">Repeater</td>
<td style="width: 85.0667%;">Simple tool that can be used to manually test an application.  It can be used to modify requests to the server, resend them, and observe the results.</td>
</tr>
<tr>
<td style="width: 14.8%;">Decoder</td>
<td style="width: 85.0667%;">Tool to convert encrypted data into its canonical form or to convert raw data into various encrypted and hashed forms.  It is capable of intelligently recognizing several encoding formats using heuristic techniques.</td>
</tr>
<tr>
<td style="width: 14.8%;">Comparer</td>
<td style="width: 85.0667%;">Make a comparison (a visual difference) between any two data items.</td>
</tr>
<tr>
<td style="width: 14.8%;">Extender</td>
<td style="width: 85.0667%;">Allows security testers to load Burp extensions, to extend Burp functionality using third-party or security testers (BAppStore) code</td>
</tr>
<tr>
<td style="width: 14.8%;">Sequencer</td>
<td style="width: 85.0667%;">Randomly analyze the data sample sent.  It can be used to check for unpredictable application sessions, such as anti-CSRF tokens, password reset notifications, etc.</td>
</tr>
</tbody>
</table>
<h2 id="ftoc-cach-cai-dat-va-active-burp-suite-2022-11-pro-full-key" class="ftwp-heading">How to install and Active Burp Suite 2022.11 Pro Full Key</h2>
<p>Do Burp Suite 2022.11 Pro <strong>Runs on Java platform</strong>so you need to install Java first, download the full installer from the link below:</p>
<p style="text-align: center;"><a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.fshare.vn%2Ffile%2FI9DVZ21O2XAB" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';"><span style="text-decoration: underline;"><strong><span style="font-size: 14pt;">Download Burp Suite 2022.11 Pro Full Key</span></strong></span></a></p>
<p style="text-align: center;"><span style="color: #3366ff;"><strong>(Password: anonyviet.com)</strong></span></p>
<p><strong>Step 1:</strong> Install <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fwww.fshare.vn%2Ffile%2FSIS7CW6VL5LC" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">JAVA</a> on Windows</p>
<p><strong>Step 2: </strong>Run the file reset_license.bat if Burp Suite is already installed on the computer.</p>
<p><strong>Step 3: </strong>Run File step1.bat, then <strong>uncheck</strong> “help improve burp by …” and select “I Accept”</p>
<p><strong>Step 4: </strong>Run the file step2.bat</p>
<p><strong>Step 5:</strong> press <strong>RUN</strong> to open Burp</p>
<p><strong>Step 6:</strong> Copy License -> Next -> Copy Code back and forth BurpLoaderKeygen to Get Key, Copy Key back and forth to Active</p>
<p><strong>Step 7:</strong> burpsuite_pro_v2022.11 to Active Key (see picture below for details)</p>
</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2F2-enter-license-key-burp-suite.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter wp-image-24619 size-full" src="https://anonyviet.com/wp-content/uploads/2019/11/2-enter-license-key-burp-suite.jpg" alt="active burp suite License Text" width="941" height="336" srcset="https://anonyviet.com/wp-content/uploads/2019/11/2-enter-license-key-burp-suite.jpg 941w, https://anonyviet.com/wp-content/uploads/2019/11/2-enter-license-key-burp-suite-300x107.jpg 300w, https://anonyviet.com/wp-content/uploads/2019/11/2-enter-license-key-burp-suite-768x274.jpg 768w, https://anonyviet.com/wp-content/uploads/2019/11/2-enter-license-key-burp-suite-750x268.jpg 750w" sizes="auto, (max-width: 941px) 100vw, 941px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 12"/></a></p>
<p>Select <strong>Manual activation</strong></p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2F3-manual-activation.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter wp-image-24620 size-full" src="https://anonyviet.com/wp-content/uploads/2019/11/3-manual-activation.jpg" alt="Manual activation burp suite" width="386" height="317" srcset="https://anonyviet.com/wp-content/uploads/2019/11/3-manual-activation.jpg 386w, https://anonyviet.com/wp-content/uploads/2019/11/3-manual-activation-300x246.jpg 300w" sizes="auto, (max-width: 386px) 100vw, 386px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 13"/></a></p>
<p>Click “<strong>Copy request</strong>“, and paste it back in the “<strong>Activation Request </strong>by Loader</p>
<p>Copy the line &#8220;<strong>Activation Response</strong>&#8220;re-enter&#8221; <strong>Manual Activation</strong>click &#8220;<strong>Paste response</strong>“, and click “<strong>next</strong>&#8220;</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2F4-activation-response.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter wp-image-24621 size-full" src="https://anonyviet.com/wp-content/uploads/2019/11/4-activation-response.jpg" alt="Activation Response burp suite" width="990" height="346" srcset="https://anonyviet.com/wp-content/uploads/2019/11/4-activation-response.jpg 990w, https://anonyviet.com/wp-content/uploads/2019/11/4-activation-response-300x105.jpg 300w, https://anonyviet.com/wp-content/uploads/2019/11/4-activation-response-768x268.jpg 768w, https://anonyviet.com/wp-content/uploads/2019/11/4-activation-response-750x262.jpg 750w" sizes="auto, (max-width: 990px) 100vw, 990px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 14"/></a></p>
<p>A successful Active Burp Suite message will appear.</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2Factived.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter wp-image-24622 size-full" src="https://anonyviet.com/wp-content/uploads/2019/11/actived.jpg" alt="Active Burp Suite" width="342" height="80" srcset="https://anonyviet.com/wp-content/uploads/2019/11/actived.jpg 342w, https://anonyviet.com/wp-content/uploads/2019/11/actived-300x70.jpg 300w" sizes="auto, (max-width: 342px) 100vw, 342px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 15"/></a></p>
<p>Fix Burp suite not opening:</p>
<p>Open CMD and point to the downloaded and unzipped folder</p>
<p>Enter the command in CMD:<br /><code>java --illegal-access=permit -Dfile.encoding=utf-8 -javaagent:BurpSuiteLoader_v2022.11.jar -noverify -jar burpsuite_pro_v2022.11.jar</code></p>
<p>Wait until the Enter License Key window appears</p>
<p><a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fwp-content%2Fuploads%2F2019%2F11%2F1-burp-suite-license-key-1.jpg" rel="noopener" class="local-link"><img decoding="async" loading="lazy" class="aligncenter size-full wp-image-24617" src="https://anonyviet.com/wp-content/uploads/2019/11/1-burp-suite-license-key-1.jpg" alt="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 3" width="551" height="293" srcset="https://anonyviet.com/wp-content/uploads/2019/11/1-burp-suite-license-key-1.jpg 551w, https://anonyviet.com/wp-content/uploads/2019/11/1-burp-suite-license-key-1-300x160.jpg 300w" sizes="auto, (max-width: 551px) 100vw, 551px" title="Download Burp Suite 2022.11 Pro Full Key - How to Active Copyright 16"/></a></p>
<p>You have successfully activated the latest Burp Suite 2022.11.</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;16211&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;101&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (101 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (101 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/download-burp-suite-2022-11-pro-full-key-how-to-active-copyright/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2019/11/Burp-Suite-Pro-Full.jpg" medium="image"></media:content>
            	</item>
		<item>
		<title>How to use Burp Suite to exploit SQL Injection</title>
		<link>https://en.anonyviet.com/how-to-use-burp-suite-to-exploit-sql-injection/</link>
					<comments>https://en.anonyviet.com/how-to-use-burp-suite-to-exploit-sql-injection/#respond</comments>
		
		<dc:creator><![CDATA[AnonyViet]]></dc:creator>
		<pubDate>Sun, 01 Jan 2023 12:52:23 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Burp]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Injection]]></category>
		<category><![CDATA[SQL]]></category>
		<category><![CDATA[Suite]]></category>
		<guid isPermaLink="false">https://en.anonyviet.com/?p=167</guid>

					<description><![CDATA[SQL injection (SQLi) remains one of the most common web vulnerabilities today. But how to learn how to exploit it legally? It&#8217;s simple, you just need to download and configure Burp Suite Community Editionand create and set up an account in PortSwigger Labs. To exploit SQL Injection, you should first Download Burp Suite Pro to [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div id="ftwp-postcontent">
<p>SQL injection (SQLi) remains one of the most common web vulnerabilities today.  But how to learn how to exploit it legally?  It&#8217;s simple, you just need to download and configure <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fportswigger.net%2Fburp%2Fcommunitydownload" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">Burp Suite Community Edition</a>and create and set up an account in <a target="_blank" href="https://en.anonyviet.com/next-link/?url=https%3A%2F%2Fportswigger.net%2Fweb-security%2Fall-labs" rel="noopener external nofollow" class="ext-link" onclick="this.target='_blank';">PortSwigger Labs</a>.</p>
<p><img decoding="async" class="aligncenter wp-image-42790 size-full" src="https://anonyviet.com/wp-content/uploads/2022/07/1_9BtvaZq8_rkP0xtTyuMMyQ2x.jpeg" alt="Basic SQL Injection with Burp Suite" width="700" height="489" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_9BtvaZq8_rkP0xtTyuMMyQ2x.jpeg 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_9BtvaZq8_rkP0xtTyuMMyQ2x-300x210.jpeg 300w" sizes="(max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 23"/></p>
<p>To exploit SQL Injection, you should first <a target="_blank" href="https://en.anonyviet.com/next-link?url=https%3A%2F%2Fanonyviet.com%2Fdownload-burp-suite-full-key%2F" class="local-link" rel="noopener">Download Burp Suite Pro</a> to practice.</p>
<h2 id="ftoc-ke-hoach" class="ftwp-heading">Plan</h2>
<p>Task: Find Lab “SQL injection attack, list database contents on non-Oracle database”.  I chose this Lab because it shows all the steps of basic SQLi and helps you understand Burp Suite tools.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42791 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_aHt8EpDOkH6Ubqk_Coyq3w.png" alt="How to use Burp Suite to exploit SQL Injection 21" width="700" height="317" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_aHt8EpDOkH6Ubqk_Coyq3w.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_aHt8EpDOkH6Ubqk_Coyq3w-300x136.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 24"/></p>
<p>In short: find the Admin login</p>
<p>Necessary steps:</p>
<ol>
<li>Find and confirm <strong class="jy ja">Entry Point</strong> in web request</li>
<li>Learn type <strong class="jy ja">SQL comments</strong> Valid</li>
<li>Find Row number in current table</li>
<li>Find Columns that return STRING</li>
<li>Find which Table is in the database of this web application</li>
<li>Find the Target Table (Table with admin credentials)</li>
<li>Specify the Column name of the Table</li>
<li>Get content</li>
</ol>
<h2 id="ftoc-sql-injection-co-ban-voi-burp-suite" class="ftwp-heading">Basic SQL Injection with Burp Suite</h2>
<h3 id="ftoc-1-tim-va-xac-nhan-entry-point-trong-request-web" class="ftwp-heading">1. Find and confirm the Entry Point in the web request</h3>
<p>When you visit the page, you will see a normal landing page.  Our goal is to explore this page and look for parameters that are related to the database.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42792 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_Qjx6rlPvXc4RmNKVj-nbIA.png" alt="How to use Burp Suite to exploit SQL Injection 22" width="700" height="473" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_Qjx6rlPvXc4RmNKVj-nbIA.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_Qjx6rlPvXc4RmNKVj-nbIA-300x203.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 25"/></p>
<p>Here we obviously have two options: filters like &#8216;All&#8217;, &#8216;Clothing&#8217;… and My Account are at the top right.</p>
<p>Let&#8217;s focus on filters.</p>
<p>Clicking “All” will not invoke any filters.</p>
<p>So select the “Gifts” filter to get a valid response.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42793 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_u0TTA9VlPZzCWD4dBo4bsQ.png" alt="How to use Burp Suite to exploit SQL Injection 23" width="700" height="115" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_u0TTA9VlPZzCWD4dBo4bsQ.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_u0TTA9VlPZzCWD4dBo4bsQ-300x49.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 26"/></p>
<p>Now power up Burp and access its Proxy&#8217;s HTTP history.  Make sure you have Intercept turned off.  If not, it will still work but everything will be much slower… you can try it yourself.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42794 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_2ELvov-EZ_gYml4aDBL26Q.png" alt="How to use Burp Suite to exploit SQL Injection 24" width="700" height="151" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_2ELvov-EZ_gYml4aDBL26Q.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_2ELvov-EZ_gYml4aDBL26Q-300x65.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 27"/></p>
<p>Burp intercepted a Request to the Lab Application.  Now we need to edit it.  We send this Request to Repeater in Burp by right clicking on Request Body and selecting “Send to Repeater”.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42795 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_KnPIro6BZJkEi0zrxfezrA.png" alt="How to use Burp Suite to exploit SQL Injection 25" width="646" height="138" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_KnPIro6BZJkEi0zrxfezrA.png 646w, https://anonyviet.com/wp-content/uploads/2022/07/1_KnPIro6BZJkEi0zrxfezrA-300x64.png 300w" sizes="auto, (max-width: 646px) 100vw, 646px" title="How to use Burp Suite to exploit SQL Injection 28"/></p>
<p>Then go to the Repeater tab in Burp and find Request.  You can edit it now.</p>
<p>Web servers only understand URL characters and only some human readable content.  So enable automatic URL encoder in Burp by clicking Request body in Repeater and select<strong> URL-encode as you type</strong>.  Now, whenever we enter characters that are not understood by the Web server will be encoded as URL and most of the human readable characters will be preserved.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42796 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_q7a-r_6UPo5qRAXqn3aNAw.png" alt="How to use Burp Suite to exploit SQL Injection 26" width="665" height="629" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_q7a-r_6UPo5qRAXqn3aNAw.png 665w, https://anonyviet.com/wp-content/uploads/2022/07/1_q7a-r_6UPo5qRAXqn3aNAw-300x284.png 300w" sizes="auto, (max-width: 665px) 100vw, 665px" title="How to use Burp Suite to exploit SQL Injection 29"/></p>
<p>The easiest way to find entry points in SQLi is to insert Bad Characters.  Here is the basic list:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">‘&#13;
%27&#13;
“&#13;
%22&#13;
#&#13;
%23&#13;
;&#13;
%3B&#13;
)&#13;
Wildcard (*)</pre>
<p>Start testing them from top to bottom by including them in the “category” parameter.  Eg:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">?category='&#13;
</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42797 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_8HC3BPN9iMb_lqLq94ZGsg-1.png" alt="How to use Burp Suite to exploit SQL Injection 27" width="526" height="500" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_8HC3BPN9iMb_lqLq94ZGsg-1.png 526w, https://anonyviet.com/wp-content/uploads/2022/07/1_8HC3BPN9iMb_lqLq94ZGsg-1-300x285.png 300w" sizes="auto, (max-width: 526px) 100vw, 526px" title="How to use Burp Suite to exploit SQL Injection 30"/></p>
<p>Immediately after trying the first character &#8216;, an error occurred.  This is a good sign because it means that the server did not filter the request.  The symbol we sent caused an error in SQL.</p>
<p>You can automate this process with Burp Intruder.</p>
<p>We already have the entry point, which is the value of the &#8220;category&#8221; parameter after the = sign.</p>
<p>Now, we need to learn how to control this entry point as it can break valid SQL request.</p>
<p>The control is done using the appropriate comment.  Depending on the SQL type, there are different comments.  So the best way is to try all of them but most databases are MSSQL or MySQL. <img decoding="async" loading="lazy" class="size-full wp-image-42798 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_pKrjK1fvik7PJGYRE9LTvA.png" alt="How to use Burp Suite to exploit SQL Injection 28" width="700" height="783" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_pKrjK1fvik7PJGYRE9LTvA.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_pKrjK1fvik7PJGYRE9LTvA-268x300.png 268w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 31"/></p>
<p>The double dash (-) comment doesn&#8217;t generate an error, so it&#8217;s valid and we can enter valid statements before it.</p>
<h3 id="ftoc-3-tim-so-hang-trong-bang" class="ftwp-heading">3. Find the number of rows in the table</h3>
<p>To exploit a vulnerable database, you first need to find a way to pass commands to it.  Note that direct commands have no effect.</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">‘ SELECT * FROM information_schema.tables —</pre>
<p>The application returns SQL query results in its responses, so a UNION Injection attack can be used.</p>
<p>To perform the UNION attack, you need to determine the number of active table columns.</p>
<p>Number of columns: each SQL table has a certain number of columns.  To make the UNION attack work, the request after the UNION keyword needs to contain the same amount of columns as the active table has.</p>
<p>Working table: not an official SQL term but I like to use it because it fits the way SQL works on the web.  The active table is the one used by the application to provide expected responses to user requests.</p>
<p>Therefore, the number of columns can be determined using: ORDER BY.  By incrementing the number after it, we can determine the exact number of columns.</p>
<p>You will notice that &#8216;ORDER BY 1 -&#8216; produces no error but &#8216;ORDER BY 1 0—&#8217; the number of columns is greater than 1 but less than 10.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42799 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_Mw9P4FJ3e8QK6be64247cg.png" alt="How to use Burp Suite to exploit SQL Injection 29" width="700" height="758" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_Mw9P4FJ3e8QK6be64247cg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_Mw9P4FJ3e8QK6be64247cg-277x300.png 277w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 32"/></p>
<p>Tried 2 results with no errors but the 3rd one failed.  There are no more than 3 columns: there are exactly 2 columns in the active table.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42800 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_wp95FzOK1nggyQnljepdhg.png" alt="How to use Burp Suite to exploit SQL Injection 30" width="700" height="757" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_wp95FzOK1nggyQnljepdhg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_wp95FzOK1nggyQnljepdhg-277x300.png 277w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 33"/></p>
<h3 id="ftoc-4-tim-cac-cot-tra-ve-string" class="ftwp-heading">4. Find columns that return STRING</h3>
<p>Now, we know the number of columns, but we need to know which columns should provide the response.  Only columns with data type CHAR and the like can return human readable information.</p>
<p>This can be checked with a UNION SELECT query.  It works by combining the results of multiple select statements.  The first select statement provides information from the active table, but since we are locking down the first query, it provides nothing.  After UNION is the next select statement.  This statement is just an empty query but it gets the output along with the empty results from the latest query.</p>
<p>Enter a random string in each column:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">‘ UNION SELECT ‘a’, ‘b’ —</pre>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42801 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_JcI3aIUQgUjloyvvkFz0cg.png" alt="How to use Burp Suite to exploit SQL Injection 31" width="700" height="765" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_JcI3aIUQgUjloyvvkFz0cg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_JcI3aIUQgUjloyvvkFz0cg-275x300.png 275w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 34"/></p>
<p>The answer prints both a and b.  So both columns are mineable.</p>
<p>Let&#8217;s use the first column for the response and nullify the second column with NULL.</p>
<p>What we need in response is the table name, which in normal conditions would be identified with:</p>
<pre class="EnlighterJSRAW" data-enlighter-language="generic">SELECT table_name FROM information_schema.tables</pre>
<p>information_schema is an important table in any SQL Database.  It contains all the table names, columns and other cool stuff.</p>
<p>So we ask it to give us all the tables that can be stored in the DB so that we can manually choose the most suitable ones.</p>
<p>Integrating the select query above into the UNION SELECT statement yields:</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42802 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_6IAo4QKQKy-hgbKbq79jzg.png" alt="How to use Burp Suite to exploit SQL Injection 32" width="700" height="783" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_6IAo4QKQKy-hgbKbq79jzg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_6IAo4QKQKy-hgbKbq79jzg-268x300.png 268w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 35"/></p>
<p>The injected query will find multiple tables.  Normally, you would select the Search field in Burp&#8217;s response to find keywords like <strong class="jy ja">admin, users, credentials, passwords</strong>…</p>
<p>The first keyword is Administrable_role_authorizations due to the word admin contained in it.  Let&#8217;s see what the column names in this table are.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42803 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_uyq9Bzwbnp5RT-e8T8YkAg.png" alt="How to use Burp Suite to exploit SQL Injection 33" width="700" height="681" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_uyq9Bzwbnp5RT-e8T8YkAg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_uyq9Bzwbnp5RT-e8T8YkAg-300x292.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 36"/></p>
<p>Nothing stands out… So let&#8217;s skip this table.</p>
<p>The next table is users_spkopw due to the word <strong class="jy ja">users </strong>Inside.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42804 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_kUacn3Idl-y4xOjIIPeWEA.png" alt="How to use Burp Suite to exploit SQL Injection 34" width="700" height="686" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_kUacn3Idl-y4xOjIIPeWEA.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_kUacn3Idl-y4xOjIIPeWEA-300x294.png 300w, https://anonyviet.com/wp-content/uploads/2022/07/1_kUacn3Idl-y4xOjIIPeWEA-75x75.png 75w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 37"/></p>
<p>Query column names.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42805 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_R2f3GthmR_MuhsB0oFUJHg.png" alt="How to use Burp Suite to exploit SQL Injection 35" width="700" height="604" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_R2f3GthmR_MuhsB0oFUJHg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_R2f3GthmR_MuhsB0oFUJHg-300x259.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 38"/></p>
<p>It&#8217;s better.  Please output the contents of the columns in this table.  This time, we&#8217;ll output the response in both UNION columns.</p>
<p><img decoding="async" loading="lazy" class="size-full wp-image-42806 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_J9AWAXxYFSlUKlBzrT1Hag.png" alt="How to use Burp Suite to exploit SQL Injection 36" width="700" height="747" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_J9AWAXxYFSlUKlBzrT1Hag.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_J9AWAXxYFSlUKlBzrT1Hag-281x300.png 281w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 39"/></p>
<p>There are several logins, but admin is what we need.  Now go to the login page and use them.</p>
<p><img post-id="167" fifu-featured="1" decoding="async" loading="lazy" class="size-full wp-image-42807 aligncenter" src="https://anonyviet.com/wp-content/uploads/2022/07/1_V69JKtBGxI8YZ-9hktAzqg.png" alt="How to use Burp Suite to exploit SQL Injection" title="How to use Burp Suite to exploit SQL Injection" width="700" height="372" srcset="https://anonyviet.com/wp-content/uploads/2022/07/1_V69JKtBGxI8YZ-9hktAzqg.png 700w, https://anonyviet.com/wp-content/uploads/2022/07/1_V69JKtBGxI8YZ-9hktAzqg-300x159.png 300w" sizes="auto, (max-width: 700px) 100vw, 700px" title="How to use Burp Suite to exploit SQL Injection 40"/></p>
<p>So that&#8217;s a success.</p>
</p>
<div class="kk-star-ratings kksr-auto kksr-align-right kksr-valign-bottom" data-payload="{&quot;align&quot;:&quot;right&quot;,&quot;id&quot;:&quot;42788&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;bottom&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;100&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;5&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;\u0110\u00e1nh gi\u00e1 b\u00e0i vi\u1ebft post&quot;,&quot;legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: 5\/5 - (100 b\u00ecnh ch\u1ecdn)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;width&quot;:&quot;142.5&quot;,&quot;_legend&quot;:&quot;B\u00e0i vi\u1ebft \u0111\u1ea1t: {score}\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}">
<p>            The article achieved: 5/5 &#8211; (100 votes)    </p>
</p></div>
</div>
]]></content:encoded>
					
					<wfw:commentRss>https://en.anonyviet.com/how-to-use-burp-suite-to-exploit-sql-injection/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<media:content url="https://anonyviet.com/wp-content/uploads/2022/07/1_V69JKtBGxI8YZ-9hktAzqg.png" medium="image"></media:content>
            	</item>
	</channel>
</rss>
