Web Application
Burp Suite is a comprehensive web application security testing platform. It can intercept HTTP/HTTPS traffic, spider websites, scan for vulnerabilities, and includes tools for manual testing like Repeater and Intruder.
sudo apt install burpsuite
burpsuite (GUI application)
Burp Suite is the industry-standard platform for web application security testing. Developed by PortSwigger, it provides a comprehensive toolkit for intercepting HTTP/HTTPS traffic, mapping application attack surfaces, automating attacks, and reporting vulnerabilities.
The platform includes the Proxy for traffic interception, Scanner for automated vulnerability detection, Intruder for customized automated attacks, Repeater for manual request modification, and Decoder for data format manipulation. Extensions from the BApp Store add virtually unlimited functionality.
Security professionals use Burp Suite for every phase of web application testing from initial reconnaissance to exploitation and reporting. Its combination of automated and manual testing tools makes it essential for professional penetration testers.
burpsuiteLaunch Burp Suite - Opens the main graphical user interface applicationConfigure browser proxy: 127.0.0.1:8080Setup proxy - Route web browser traffic locally through the Burp listenerProxy > Intercept > Intercept is onEnable interception - Pause and capture outgoing HTTP requests for inspectionRight-click request > Send to RepeaterUse Repeater - Manually modify and resend individual requests to analyze behavioral changesRight-click request > Send to IntruderUse Intruder - Launch automated customizable payload testing for parameter fuzzingCtrl+R / Ctrl+IShortcuts - Send the selected request to Repeater or IntruderTarget > Site mapSite map - Review the discovered structure of the target applicationDecoder > Encode/DecodeDecoder - Encode or decode data (Base64, URL, HTML, hex)Comparer > Compare (words/bytes)Comparer - Diff two responses to spot subtle differencesExtensions > BApp StoreExtensions - Install add-ons like Logger++ or Autorizejava -jar -Xmx2g burpsuite_pro.jarHeap size - Launch Burp with more memory for large scansProxy > Options > Import / export CA certificateCA cert - Export Burp's root CA to trust HTTPS interceptionIntercept and modify HTTP/HTTPS requests and responses in real-time between browser and server.
Automatically scan web applications for SQL injection, XSS, CSRF, and hundreds of other vulnerabilities.
Use Intruder to perform brute-force, fuzzing, and parameter testing with customizable payload positions.
Send individual requests to Repeater for manual modification, resending, and response analysis.
Analyze session tokens, cookies, and authentication mechanisms for security weaknesses.
Test REST, GraphQL, and WebSocket APIs for authentication, injection, and business logic flaws.
Test login mechanisms, session management, and access control by intercepting and manipulating authentication requests.
Identify flaws in application logic such as price manipulation, privilege escalation, and workflow bypass by modifying request parameters.
Manipulate HTTP headers and cache keys to inject malicious responses into cached content served to other users.
Test file upload functionality for unrestricted file types, path traversal, and remote code execution vulnerabilities.
Burp Suite Professional requires 4 GB RAM minimum (8 GB recommended), a modern multi-core CPU, and 2 GB free disk space. It runs on Windows 10+, macOS 10.14+, and Linux with Java 11 or later. Community Edition has lower resource needs but Pro is recommended for serious testing.
Repeater is manual — you send individual modified requests one at a time and inspect responses. Intruder is automated — it takes a base request, defines payload positions, and iterates through a payload list (wordlists, ranges, brute-force) at high speed, then allows you to filter results by response attributes like length or status code.
Open the Extender tab in Burp Suite, go to the BApp Store sub-tab, and browse or search for extensions by category. Click Install to add them. You can also manually install Python or Java extensions from the Extensions > Extensions > Add menu using .py or .jar files.
Passive scanning analyzes traffic that flows through the proxy without sending additional requests — it checks for missing security headers, cookie flags, and information disclosure. Active scanning sends crafted payloads to identified parameters to test for SQL injection, XSS, command injection, and other input-based vulnerabilities.
Yes. Projects saved in Community Edition open directly in Professional. The main differences are that Pro adds automated scanning, Intruder with no speed limit, session handling rules, and project file storage. Your proxy history, target scope, and Repeater tabs transfer seamlessly between editions.
Import API definitions (OpenAPI/Swagger, WADL, WSDL) via the Target tab to build a structured site map. Use the API Tester tab or Repeater to craft requests with proper authentication. Test for IDOR by manipulating resource IDs, check for broken authentication by varying tokens, and use Intruder for parameter fuzzing against API endpoints.
Web Application
Free and open source web application security scanner with automated scanning and CI/CD integration.
Vulnerability Analysis
Open source web server scanner that detects misconfigurations, outdated software, and dangerous files.
Web Application
Automated SQL injection detection and exploitation tool with database fingerprinting and data extraction.
Web Application
Advanced XSS detection suite with context-aware payload generation and WAF bypass techniques.
Vulnerability Analysis
Open source web application vulnerability scanner with command-line interface and automated crawling.
Web Application
Fast web fuzzer for directory, subdomain, and parameter discovery with high-speed brute-force capabilities.
The interface provides granular control over web traffic. It maps the site layout, details every intercepted interaction, and categorizes identified risks based on their potential impact.
This tool is designed for authorized security testing, educational purposes, and legitimate network administration only. Unauthorized access to computer systems is illegal.