Burpsuite
Getting Started with Burpsuite & Running a basic Web-Spider
Burpsuite is a collection of tools
bundled into a single suite made for Web Application Security or
Penetration testing. Its a java executable and hence its cross platform.
Kali Linux comes with Buprsuite free edition installed. There is also a
professional version available. The main features of burpsuite is that
it can function as an intercepting proxy. Burpsuite intercepts the
traffic between a web browser and the web server.
data:image/s3,"s3://crabby-images/65bae/65baec43edf76f15f690b0923cd5ba070065f2ec" alt="burpsuite"
Other Features include:
- Application Aware Spider : Used for spidering/crawling a given scope of pages.
- Scanner : Automatically scans for vulnerabilities just like any other automated scanners
- Intruder : Used to perform attacks & bruteforces on pages in a highly customize-able manner.
- Repeater : Used for manipulating and resending individual requests.
- Sequencer : Used mainly for testing/fuzzing session tokens.
- Extensibility, allowing you to easily write your own plugins, to perform complex and highly customized tasks within Burp.
- Comparer & Decoder used for misc purposes that might come along the way when you conduct a Web Security test
Spidering a Website
A web crawler is a bot program which systematically browses the pages of a website for the purpose of indexing. Precisely a web crawler maps the structure of a website by browsing all its inner pages. The crawler is also reffered to as spider or automatic indexer.Burpsuite has got its own spider called the burpspider. The burp spider is a program which crawls into all the pages of a target specified in the scope. Before starting the burp spider, burpsuite has to to be configured to intercept the HTTP traffic.
Interface & Options
Like any other GUI/Windows tool, burpsuite contains a standard menu bar, 2 rows of tabs & different set of panels as seen below.data:image/s3,"s3://crabby-images/58f27/58f27030d8fd4ee2832726d22941afa4eccc8bd6" alt="Burpsuite"
- Tool & Options selector Tabs – Select between Various tools & settings of burpsuite
- Sitemap View – Displays the sitemap once spider has started
- Requests Queue – Displays the requests being made
- Request/Response Details – The HTTP requests made & the responses from the servers.
Lab 1 : Spidering a website
Spidering is a major part of recon while performing Web security tests. It helps the pentester to identify the scope & archetecture of the web-application.As described earlier, burpsuite has it’s own spider called the burp spider which can crawl into a website.Scenario: Attacker – Kali Linux VM, IP = 192.168.0.105
Target – OWASP Broken Web Application VM, IP = 192.168.0.160
Download OWASPBWA
Step 1 : Setup Proxy.
First start burpsuite and check details under proxy tab in Options sub-tab. Ensure IP is localhost IP & port is 8080.
data:image/s3,"s3://crabby-images/d603f/d603fed828227e2c4cbe474ef2138cd05ad26050" alt="burpsuite"
data:image/s3,"s3://crabby-images/c3535/c35358e1d5a2dc6bfcac53b766ecdac2dd1cf0e2" alt="burpsuite"
Choose Manual Proxy Configuration
data:image/s3,"s3://crabby-images/74fc0/74fc005dfaa1f759f5e63d4096736933c9dbc342" alt="Burpsuite"
Install the proxy selector from addons page and goto preferences
data:image/s3,"s3://crabby-images/8b841/8b84152d37e2a0c5470a7e64512eadeb0fb74bd5" alt="burpsuite"
Goto Manage Proxies & add a new proxy filling out the relevant information. It’s simple.
data:image/s3,"s3://crabby-images/5f2e8/5f2e8860c24902fdfaf24cbdf3d08bdbd528931e" alt="burpsuite"
data:image/s3,"s3://crabby-images/bcc52/bcc52cc6589dbd88461c158ac237815c9eb26a68" alt="burpsuite"
After you have setup the proxy, goto the target normally by entering the URL in the address bar. You can notice that the page will not be loading up. This is because burpsuite is intercepting the connection.
data:image/s3,"s3://crabby-images/91aed/91aed4c0dcdc462f48e4ad753979833bfd2d78f8" alt="burpsuite"
data:image/s3,"s3://crabby-images/23691/23691b3d1df3996c5fc257e03fcbc5317ba6606a" alt="burpsuite"
data:image/s3,"s3://crabby-images/c7cc9/c7cc99e7c5198580b5679e0288f2e725c8a22970" alt="burpsuite"
data:image/s3,"s3://crabby-images/57ef1/57ef1d761c9688cf633a96f3b59cf1d92a4d08eb" alt="burpsuite"
Now narrow down the target as you want. Here the target/mutillidae is selected. Right click the mutillidae from the sitemap & select Spider from Here option
data:image/s3,"s3://crabby-images/4ee6e/4ee6e9cf4ce53abf8f9a33269631ee9c237527b8" alt="burpsuite"
data:image/s3,"s3://crabby-images/c17cd/c17cd28bf3c813e01f8fa98b4590af5ee91b760c" alt="burpsuite"
Step 4 : Manipulating Details
Now you can see as the spider runs, the tree inside of the mutillidae branch gets populated. Also the requests made are shown in the queue and the details are shown in the Request tab.
data:image/s3,"s3://crabby-images/4794a/4794a4858aeac0bdd5eb07419695753cd17cd16e" alt="burpsuite"
data:image/s3,"s3://crabby-images/71ace/71acefda0f7d9cb8efd0b912944456bd75682b53" alt="burpsuite"
data:image/s3,"s3://crabby-images/06291/062912eabbd1bd7a47040e35379b37ea9466afa6" alt="burpsuite"
data:image/s3,"s3://crabby-images/16e3a/16e3ae577c5adf5c3cece3f9bf0e2b50fdceae39" alt="burpsuite"
data:image/s3,"s3://crabby-images/264e6/264e602a58784e1a02ceb0c55a7c23ae02abd6d3" alt="burpsuite"
These are the very basics & starting point of a web security test. Spidering is an important part of the recon during the test and by clearly executing this, we can understand about the architecture of the target site. In upcomming tutorials, we will extend this to other tools in the Burpsuite set of tools.
Thanks. In this article django vs rails, we will look at their Meaning, Head to Head Comparison, Key Differences, and Conclusion in a relatively easy and simple ways.
ReplyDelete