using intercepting Proxies
are learning objectives. Would understand what an intercepting proxy is demonstrate how to set up Burp suite. Community Edition. No the different tools within Burp suite such as repeater, an intruder and decoder. And also understand Oas zap or zed attack Proxy
Burp suite. If you're anywhere in the web application security space, you should know what burp suite is. Um It is by by far, hands down the most popular um intercepting proxy out there. It's made by Port Swiger in the U. K. They have a free academy
at ports of your Net
I would highly recommend you go out there and you use these labs. I've done many of their labs
on various things, things not an O SCP things that are no SCP um you know, very complex topics such as like HTP requests, smuggling
or srf. So I think port swagger does a very great job
and their hands down if you want to do web application security,
they have the Academy for that.
The community edition of Burp suite is in Cali Lennox.
Um If you're going to be doing things like bug bounty or you're a professional web pen tester,
you really need to buy the pro version. It is. There's so many great features and functionality like active scan. Um
The only thing is you're allowed to use it in. Oh SCP So if you even if you have it you can't use it in. Oh SCP.
Uh What happened was there was this great spider ring feature in Burp suite that they removed in version two.
Some people prefer using version 1.7 which still have spider ring in it. Just because there
really in love with that feature and they don't want to migrate to the newer version because they want to be able to spider different web applications.
So if you have Burp suite you need to install their certificate authority.
Burp suite has his own C. A. Which you can get by going to http. Burp suite and downloading and then you'll have to import that into your browser.
That will mitigate issues of you going to h D h T T p S sites
and getting an error that pops up. So make sure that you install the Burp suite CIA into your browser
when you use it. Especially when going to https sites.
If you do a lot of capture the flag is typically things are on port 80 or they don't have https so you won't notice this. But if you're going to these https sites you really need to install the certificate authority.
Also I think this embedded browser which came about recently is a game changer. I really like it because I don't have to worry about installing the certificate authority in Firefox or chromium. I can use burps embedded browser and just put everything in there. And then I have to browsers. I have one that I don't have to
route through Burp suite
and the other one that is going through Burp suite.
So the proxy why why we call an intercepting proxy? Um it's because
it intercepts the traffic between our web browser
The other thing is if you've used this before and you type in a web page and hit enter and you see nothing happens.
You know, that's because you forgot to turn intercept off or from on to off. I should say it's on by default. So
that means it's just going to sit there and it's just going to wait for you to turn off the proxy.
So ensure that when you start a Burp suite you turn intercept to off.
It's called intercepting proxy Because you can modify the packets
we saw Net Cat and we changed we downgraded http to 1.0. Well you can do that a lot easier using an intercepting proxy. You can change things from get requests to post requests. Get requests meaning you're getting a website post request, meaning you're posting data like you're entering a username and password
so you can do that easily here using Burp suite.
So repeat er I really like repeater because you can easily analyse different types of requests. You can see a post request here. I can easily change that into a get request
by changing the request method.
I can easily analyse the response. Maybe I want to change the password to something else
and I can quickly do that here as opposed to going through the browser. If I want to test a sequel injection, I can quickly do that here as opposed to having to look at the browser over and over and over every time I send a different request.
So repeater allows you to send different types of requests and analyze the response.
Intruder. Intruder takes a little bit of getting used to um, it's used for brute forcing logins. You can fuzz web applications,
you'll notice that it's throttled in the community edition. So if you're going to do things like brute forcing username and password, Hydro might be a better tool for you to use. You can read specific strings. So if I know when I log in, I see something that's his administrator,
I can grip for that. I'll show you that in the demo
but you need to specify positions. So
I'll show you the different types of payloads. I typically use sniper,
so I'll typically use one value or change one value
and that usually works well for me. You can use battering ram which places the same payload value in all the positions as opposed to just one. You can use pitchfork
or you can use cluster bomb. Um
I don't talk about this here, but you if you use something like shell shock,
cluster bomb might be a great place for that. Uh or even battering ram um as well. So
just get to know these different types of payloads. Again, sniper is usually my go to uh payload type,
There's also decoder. So you can see here we have a base 64 encoded value that decodes the cyber is awesome,
But you can decode and encode things like base 64 URL. HTML.
So there's a lot of different options here, as far as encoding and decoding.
Um Sometimes you have to your l encode different payload types
so you can do that all in burp suite. Another great tool. You can use a cyber chef
and the link is down there. That's another great site for decoding things or encoding things.
or is that attack proxy?
I don't think it's as popular as burp suite. It does have a spider ring function to it which makes it really great.
It's very noisy of course it's already installed in Cali
some people like Bert better. Some people like zap better. I'm gonna demonstrate both. So you can kind of compare the two and see which one you like. But I recommend trying both of them seeing which one you like.
So here's our quiz question.
Which feature was removed from Burp 1- 2?
Was it the built in browser. Active scanner or the Spider?
So I'm gonna do the summary and then I'm going to jump right into the demo. But in summary we should understand what an intercepting proxy is.
I will now demonstrate how to set up Burp Suite community edition for you.
You should know the different tools within Burp Suite, such as repeater, intruder and decoder and you should understand Oas zap or Zed attack proxy. So stay tuned for the demo.