Tryhackme-BurpSuite

Burp Suite

Burp Suite: The Basics

Task1 Introduction Outline

Deploy the machine attached to the task by pressing the green “Start Machine” button, as well as the AttackBox (using the “Start AttackBox” button at the top of the page) if you are not using your own machine.

Task2 Getting Started What is Burp Suite?

1.Which edition of Burp Suite will we be using in this module?

Burp Suite Community

2.Which edition of Burp Suite runs on a server and provides constant scanning for target web apps?

Burp Suite Enterprise

3.Burp Suite is frequently used when attacking web applications and ______ applications.

mobile

Task3 Getting Started Features of Burp Community

1.Which Burp Suite feature allows us to intercept requests between ourselves and the target?

proxy

2.Which Burp tool would we use if we wanted to bruteforce a login form?

Intruder

Task4 Getting Started Installation

If you have chosen not to use the AttackBox, make sure that you have a copy of Burp Suite installed before proceeding

Task5 Getting Started The Dashboard

Open Burp Suite and have a look around the dashboard. Make sure that you are comfortable with it before moving on

Task6 Getting Started Navigation

Get comfortable navigating around the top menu bars.

Task7 Getting Started Options

1.Change the Burp Suite theme to dark mode

2.In which Project options sub-tab can you find reference to a “Cookie jar”?

sessions

3.In which User options sub-tab can you change the Burp Suite update behaviour?

Misc

4.What is the name of the section within the User options “Misc” sub-tab which allows you to change the Burp Suite keybindings?

Hotkeys

5.If we have uploaded Client-Side TLS certificates in the User options tab, can we override these on a per-project basis (Aye/Nay)?

Aye

6.There are many more configuration options available. Take the time to read through them.

In the next section, we will cover the Burp Proxy – a much more hands-on aspect of the room.

Task8 Proxy Introduction to the Burp Proxy

1.Which button would we choose to send an intercepted request to the target in Burp Proxy?

Forward

2.[Research] What is the default keybind for this?

Note: Assume you are using Windows or Linux (i.e. swap Cmd for Ctrl).

Ctrl+F

image-20210914141619360

Task9 Proxy Connecting through the Proxy

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值