Burp Suite Essential Training

Burp Suite Essential Training

1h 25mIntermediate2022-02-08

Authors

Malcolm Shore

Malcolm Shore

Cybersecurity Expert, Former Director of GCSB

Course details

Burp Suite, the popular web application penetration testing tool, has quickly become one of the preferred choices of security professionals around the world. In this course, instructor Malcolm Shore provides you with an in-depth look at how to use Burp Suite to meet all of your pen testing needs.

Explore the basics of the Burp Suite user interface as well as how to proxy web traffic and set up additional targets. Learn about using Burp Suite as both a website crawler and a man in the middle proxy for message viewing, finding missing content, and modifying and manipulating commands. Find out how Burp Suite works as an attack tool when it's in intruder mode, and how to configure CO2 as an extension that integrates with SQLMap. Along the way, Malcolm offers tips on how to take your web application penetration testing skills to the next level and beyond.

Skills covered

Burp SuitePortSwiggerPenetration TestingEssential TrainingCybersecurity

Concepts

Introduction

  • Learning how to use Burp Suite effectively
  • What you should know
  • Course disclaimer

Burp Suite Basics

  • What is Burp Suite
  • Getting to know Burp Suite
  • Proxying web traffic
  • Using Burp Suite as a proxy
  • Setting up additional targets

Scanning

  • Crawling the website
  • Finding hidden webpages
  • Understanding message content
  • Finding missing content

Man in the Middle

  • Intercepting bank transactions
  • Exploiting headers
  • Inserting an SQL injection via Burp Suite
  • Saving request messages for further exploitation
  • Injecting commands into messages

Being an Intruder

  • Introducing the Intruder
  • Manipulating cookies
  • The four Intruders

Extensions

  • Using CO2 to integrate SQLMap

Conclusion

  • Next steps
40,000 Toman