BurpSuite.guide (@burpsuiteguide) 's Twitter Profile
BurpSuite.guide

@burpsuiteguide

Your guide to all things Burp Suite!
Subscribe to my newsletter: newsletter.burpsuite.guide

ID: 1339973675341107202

linkhttps://burpsuite.guide calendar_today18-12-2020 16:40:23

386 Tweet

3,3K Followers

23 Following

Hack Red Con (@hackredcon) 's Twitter Profile Photo

Hey, Folks! Check this weekly series with Zachary Stashis called "There's a BApp for that". It shows a technical how-to-use of certain Burp Suite Plugins to help with Penetration Testing and Bug hunting. hackredcon.com/there-s-a-bapp… #cybersecurity #pentesting #HackRedCon

Soroush Dalili (@irsdl) 's Twitter Profile Photo

#BurpSuite Sharpener extension has been updated to version 1.9 to remember last size & position of Burp Suite as well as detecting whether it is off-screen! It also includes a number of important bug fixes: github.com/mdsecresearch/… Hopefully BApp Store will update it soon too.

PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

How we tune Burp Suite's performance: - "Proxy->Options->Misc->Don't send items to Proxy history or live tasks, if out of scope" - Enable "Project Options->HTTP->{keep-alive,HTTP/2}" - Disable live-tasks & extensions

Hack Red Con (@hackredcon) 's Twitter Profile Photo

For this week's "There's a BApp for that", Zach shows how to use Stepper, a natural evolution of Burp Suite's Repeater tool to help automate “second-order” attacks. hackredcon.com/post/there-s-a… #burpsuite #pentester #cybersecurity #infosec #cybersecuritytips #HackRedCon

PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

It's worth knowing Burp Suite project files are memory mapped. This means they reduce RAM consumption, but don't support garbage collection (yet) so deleting requests frees up RAM for Burp, but doesn't reduce file size. For long-term storage, use 'Project->Save copy' then zip.

Burp Suite (@burp_suite) 's Twitter Profile Photo

Burp Suite 2022.7.1 released to the Stable channel. You can now configure tab-specific options for Repeater and automatically detect client-side prototype pollution sources using Burp Scanner. portswigger.net/burp/releases/…

PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

We've prototyped a new feature in repeater where we are diffing the last response with the current and showing different colours depending on what changes. Please check it out we'd love your feedback! portswigger.net/bappstore/902e…

Burp Suite (@burp_suite) 's Twitter Profile Photo

Burp Suite 2022.8.1 released to the Stable channel, with new scan checks based on the Browser-Powered Desync Attacks presented by James Kettle at Black Hat 2022, as well as new Repeater capabilities that let you test for these vulnerabilities manually. portswigger.net/burp/releases/…

James Kettle (@albinowax) 's Twitter Profile Photo

Hope you enjoyed the talk, thanks for coming! Always a pleasure to present to a DEF CON crowd. Time for a couple drinks, then on to the next research for me. You can find the sides&whitepaper here: portswigger.net/research/brows…

Burp Suite (@burp_suite) 's Twitter Profile Photo

Burp Suite 2022.9.1 released to the Early Adopter channel. Includes an upgrade to Burp's browser and various bug fixes. portswigger.net/burp/releases/…

James Kettle (@albinowax) 's Twitter Profile Photo

Last week I published a number of novel CL.0 desync techniques, alongside advice on tuning your research to outwit the competition. Next week, a way to turn a 'medium' severity flaw into a crit with a $12k case study. And no it's not XSS :) portswigger.net/research/how-t…

Last week I published a number of novel CL.0 desync techniques, alongside advice on tuning your research to outwit the competition. 

Next week, a way to turn a 'medium' severity flaw into a crit with a $12k case study. And no it's not XSS :)

portswigger.net/research/how-t…
Burp Suite (@burp_suite) 's Twitter Profile Photo

Introducing the brand new flavour of Burp Suite - completely free, and available for a CI/CD pipeline near you … #cicd #dast portswigger.net/blog/free-dast…