Video description
Expand your knowledge of Burp Suite beyond just capturing the request and responses. Burp Suite is a freely available and one of the most widely accepted penetration testing tools to discover vulnerabilities and attacks.
Burp Suite as an integrated platform has an advanced set of tools and interfaces to perform security testing. Its various tools work seamlessly together to support the entire security testing process, from initial mapping and analysis of an application’s attack surface to finding and exploiting security vulnerabilities. In this course, you will learn hands-on techniques for attacking web applications and web services using Burp Suite. Firstly, you will learn about scoping and mapping your target application properly. Next, you will spend some time analyzing the application attack surface and scanning to trigger potential security vulnerabilities in your target, then digging deep into the results to validate your findings. Finally, you will wrap up by learning how to properly customize and report your results to your audience.
By the end of this course, you will have a working knowledge of Burp Suite and be able to perform all these techniques at a comfortable and efficient level to better perform your job as a pentester.
Table of Contents
Chapter 1: Setting Up Your Burp Suite Environment
Course Overview
Burp Suite Introduction and Proxy Configuration
Web Application Proxy Service
Launch Burp Suite for Target
Trusting Burp CA Certificate
Installation of CA Certificate
Chapter 2: Fast and Hybrid Spidering Your Web Application
About Spidering Process
Spidering in Community Edition – Previous Version
Spidering in Community Edition – Latest Version
Chapter 3: Scanning Your Web Application
About Scanning Process
OWASP Top 10 Web Vulnerabilities
Example - Brute Force Attack
Chapter 4: Exploiting Vulnerabilities in Your Web Application
SQL Injection Attack
Cross Site Scripting Attack
Cookie Management Issues
Chapter 5: Deep-Dive Analysis of Report
Burp Suite Report Format
Generating Reports
Analyze Report
Reviewing Bug Bounty