Plausible Trout
Plausible Trout
  • 1
  • 144 062
Automated Web Testing with Burp Suite Pro
A quick guide for beginners on using Burp Suite Pro to do only automated testing of web apps. Burp can do a whole lot more, but the Scanner module is very capable and often finds issues the "big guys" miss.
Переглядів: 144 062

Відео

КОМЕНТАРІ

  • @Jake-nh4ek
    @Jake-nh4ek 3 роки тому

    Can we please get an updated video with the new Burp Suite Pro?

  • @PhilSmith1
    @PhilSmith1 3 роки тому

    Video needs an update to Burp Suite Professional v2021.4.2

  • @Free.Education786
    @Free.Education786 4 роки тому

    Awesome. How to exploit highlighted vulnerabilities to check false positive vulnerabilities. Thanks

  • @a3logics478
    @a3logics478 4 роки тому

    Hi, I am Scarlett from A3logics. I want to collaborate over UA-cam. Please share your email. So I can share exact details.

  • @JamesBrodski
    @JamesBrodski 4 роки тому

    Great video, sir! It is very helpful.

  • @cbyogeesha
    @cbyogeesha 4 роки тому

    Wonderful session. You have clarified most of my queries. Thanks

  • @SR-eg6px
    @SR-eg6px 4 роки тому

    thanks a lot.. i learnt more

  • @chaos5344
    @chaos5344 4 роки тому

    cool vedio,thankyou for this ,its really helpful

    • @elitegaming883
      @elitegaming883 4 роки тому

      He is using burpsuite tool in kali Linux

  • @inspirationeveryday1175
    @inspirationeveryday1175 4 роки тому

    Excellent Video but why you don't use KALI LINUX ?

  • @anniiket
    @anniiket 4 роки тому

    The music is very irritating and distracting :(

  • @liluna6731
    @liluna6731 5 років тому

    Ive been using nmap, hydra, medusa, metasploit etc on kali , but just found burpsuite out of curiosity.

    • @0xsunil
      @0xsunil 4 роки тому

      @Adrian Dostoevsky LOL

  • @DHRUUVable
    @DHRUUVable 5 років тому

    I don't have scanner and spider tab

  • @TechRoady
    @TechRoady 5 років тому

    i set up BurpSuite on my firefox done all proxy settings but after i use proxy @t my internet is not work. If my internet is not work no any web site will be load :(

    • @shackyt
      @shackyt 5 років тому

      If intercepter is on you should forward the request for website to load.

    • @TechRoady
      @TechRoady 5 років тому

      @@shackyt ohh yeah its work thanks

    • @haramistatus1950
      @haramistatus1950 4 роки тому

      Install brup plugins in your b

  • @scriptkiddie6107
    @scriptkiddie6107 5 років тому

    EP0# Installing and Setup Burpsuite pro v2.0.11 for Hacking @

  • @jayseb
    @jayseb 5 років тому

    A bit rusty, I hadn't used burp pro for a few years... Nice video, clean explanations, no annoying music and sounds - exactly what I needed to get back into it. I see you're using the non beta version... What do you think of version 2? Cheers.

  • @sroDrakso
    @sroDrakso 5 років тому

    Thanks !

  • @amalprakash5387
    @amalprakash5387 5 років тому

    Great video 😇😇😇😇

  • @vactum0
    @vactum0 6 років тому

    he is copying ur video "ua-cam.com/video/bAhTyCm8j2c/v-deo.html"

  • @matiasroncallo4896
    @matiasroncallo4896 6 років тому

    Great video dude! Really clear

  • @sumudusubhashini2270
    @sumudusubhashini2270 6 років тому

    Thanks

  • @Eric-the-wise
    @Eric-the-wise 6 років тому

    i love the dub techno in the backgroud :p

  • @Nani-ie9zz
    @Nani-ie9zz 6 років тому

    Gud job sir

  • @TruthHurts-ng4sy
    @TruthHurts-ng4sy 6 років тому

    Awesome Video..many thanks....

  • @odumonarch0040
    @odumonarch0040 6 років тому

    Plausible Trout - Very nice video! I have a question....I noticed you did not cover using the "Content Discovery" function....Do you feel that it is unnecessary to use that function since we're already using the Spidering function? Thanks

    • @plausibletrout4766
      @plausibletrout4766 6 років тому

      I use it but I've never had much success with the content discovery feature. Takes forever and never seems to find the usual suspects. I get better results just using Burp Intruder with lists from FuzzDB DirBuster. There's also GoBuster tools.kali.org/web-applications/gobuster

  • @ndquochuy257
    @ndquochuy257 6 років тому

    good can ai add your skype

  • @stevenwalsh2
    @stevenwalsh2 7 років тому

    Turns out that proxy selector was malware..... It was taken down by www.reasoncoresecurity.com/proxyselectormozilla.org.xpi-64de3cab5deb0bb99d3f35da04a3e234d293c7a2.aspx

    • @plausibletrout4766
      @plausibletrout4766 6 років тому

      I've switched to FoxyProxy Standard. addons.mozilla.org/en-US/firefox/addon/foxyproxy-standard/

  • @pabloescobanjo4553
    @pabloescobanjo4553 7 років тому

    Here I just collect my bookmarks. Either use them or just ignore them: 7:55 scope 9:23 scanner 10:48 options 13:43 spider 15:45 proxy 21:15 scanner 23:09 site map 24:56 site map subfunctions like crawl site again 27:47 scan queue 33:15 report 36:14 save session 37:24 Web Hacker's Handbook

  • @rajeshpidikiti310
    @rajeshpidikiti310 7 років тому

    Thanks for the video. It is pretty good. I'm trying to do an authenticated scan. Do you have any suggestions or steps to do that?

    • @plausibletrout4766
      @plausibletrout4766 6 років тому

      Just manually browse the application with Scanner running and login. One thing to watch for: look in the Proxy History after you login to see what cookie the application uses to store the session ID (you should see a cookie being set in the Cookies column). Whatever it is, make sure the cookie name is listed in Scanner > Options > Skip server-side injections or Scanner will get logged out. Burp defaults have the most common session cookies listed (jsessionid for Java apps, PHPSESSID for PHP, etc.) but some apps use custom ones.

  • @ellisfamilyfunnyvdos
    @ellisfamilyfunnyvdos 7 років тому

    Your Awesome, and thanks so much to putting this into scope for a Noob!!!!

  • @the_gacker_hub
    @the_gacker_hub 7 років тому

    I don't know why you got 7 dislikes, such a good video.

  • @MrDuurrk
    @MrDuurrk 7 років тому

    Very nice walkthrough! I learned a great deal. I do have a question about a particular example you went over: when you tested the POST to "Sign Up!" at 20:49 but the passwords didn't match up, is there a case where that may actually be important to pass those JS checks in order to thoroughly test? I'm guessing Burp caught the POST for all of that data, so it can go back and test again, and will likely use its own data, whereby it would use the same passwords and pass a 'match comparison' check. But if not, isn't it possible that the app could potentially have some other action based on that JS validation which you wouldn't otherwise experience if you proceeded with dissimilar pwds? Thanks again for a fantastic video!

  • @N3TWORK_NINJA
    @N3TWORK_NINJA 7 років тому

    This was extremely helpful. Thank you for your time.

  • @MrSpy606
    @MrSpy606 7 років тому

    ?what is the price for this

  • @kthreddy
    @kthreddy 7 років тому

    Hey Plausible Trout. Great video with narration. Any more upcoming videos?

  • @Bhushantbn
    @Bhushantbn 7 років тому

    nice video sir

  • @DeepakRay4
    @DeepakRay4 8 років тому

    gr8 stuff ...

  • @sufiheadgirl5877
    @sufiheadgirl5877 8 років тому

    can i get scan option in burp free

    • @kthreddy
      @kthreddy 7 років тому

      No. That is the diff. between Free and Professional version. The Free version has all the Burp features except Scanner. That is explained in the beginning of the video.

    •  7 років тому

      There are some other restrictions as well, for example intruder option has time limits for fuzzing. So you can try the feature but you can't do big lists or it would take forever.

    • @akuleutmercy4794
      @akuleutmercy4794 7 років тому

      Is there a step by step proceedure of how to find/locate burp collaborator and use it for XXE ? Please help