
I show how http traffic looks like in a network sniffer and the differences between direct traffic and traffic via proxy. I also explain what happens when the traffic is encrypted with TLS and how you can install the burp certificate into a browser to seamlessly intercept encrypted web traffic.
I show how http traffic looks like in a network sniffer and the differences between direct traffic and traffic via proxy. I also explain what happens when the traffic is encrypted with TLS and how you can install the burp certificate into a browser to seamlessly intercept encrypted web traffic.
In this video I explain the differences in features between the Burp licenses, and also some pricing.
A quick introduction to the Burp interface.
The HTTP history. How interception works and some usefull proxy options.
The comparer is a fairly simple tool that is explained here.
Within the target tab we can both filter logging using the scope defintion, but also do site mappings.
Within the target tab we can both filter logging using the scope defintion, but also do site mappings.
If we want to manually try out different requests we must use the repeater.
Learn to use the intruder to brute force any field in a http request.
Learn to use the intruder to brute force any field in a http request.
To encode and decode base64 and other encoding schemes you can use the decoder.
With the sequencer you can examine the randomness of session cookies.
In this final video I will use several of the tools explained earlier together to solve a task: brute force specific fields in a poorly implemented session cookie.
In this course you will learn how to use the different components in Burp Suite to:
analyze web traffic
find vulnerabilities
do penetration tests of web applications
After this course you will be able to use Portswigger Burp Suite as your primary tool when working with web security.
It is recommended that you install the free version of Burp Suite while taking this course.