BurpSuite 30 Pro Tips
Search for:Security Resear 2020-04-29 00:54:25 Author: b1twis3.ca(查看原文) 阅读量:29 收藏

Home / / BurpSuite 30 Pro Tips

BurpSuite 30 Pro Tips April 28, 2020

[1/30] As promised! #BrupSuiteTips #infoSec #pentesting #bugbountytips
Instead of using many tools to do multiple level of encoding or string manipulation. You can do all of that and MORE using #Hackvertor extension by @garethheyes in just a couple of clicks! pic.twitter.com/40aUCnaIup

— B1twis3 | Preparing for OSEE (@fasthm00) February 14, 2020

[clip-2] pic.twitter.com/wy8dDnF062

— B1twis3 | Preparing for OSEE (@fasthm00) February 15, 2020

[3/30] #BurpSuitetips #BugHunting #pentesting #infosec
Applying session handling & macro to a 3rd party tool (Sqlmap) and excluding a cookie value from the altering. Note that I just used the profile endpoint and the /login RESTful api for testing purposes. pic.twitter.com/G1FYXLV8WC

— B1twis3 | Preparing for OSEE (@fasthm00) February 16, 2020

[4/30] #BurpSuitetips #PenTesting #BugHunting
Deploying Private BurpSuite Collaborator in AWS EC2 Instance (Automated). You could use the AWS console to do it manually as well!
Note that this is the basic implementation of the server.https://t.co/oAtqGgubEu pic.twitter.com/xapBjWNwAa

— B1twis3 | Preparing for OSEE (@fasthm00) February 20, 2020

[5/30] #BurpSuiteTips #Pentesting #bugHuntingtips
Creating sequences of requests/steps using BurpSuite extension #Stepper.
Another #Tip: No need to be an expert in #RegEx to use Stepper, just use BurpSuite Sequencer (Select! Then copy the RegEx) BUT it's good to know RegEx ofc! pic.twitter.com/s7LwoPGGk2

— B1twis3 | Preparing for OSEE (@fasthm00) February 24, 2020

To be continued…



文章来源: http://b1twis3.ca/burpsuite-30-pro-tips/
如有侵权请联系:admin#unsafe.sh