Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile
Mastering Burp Suite Pro

@masteringburp

Tips and tricks for Burp Suite Pro
Managed by @Agarri_FR | Not affiliated with @Portswigger

More free resources at hackademy.agarri.fr/freebies

ID: 1303342222650355712

linkhttps://hackademy.agarri.fr/ calendar_today08-09-2020 14:39:41

1,1K Tweet

15,15K Followers

0 Following

Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

If you never used the Piper extension, I recommend to watch the 4-minute demo I gave last year during my talk at NorthSec 🛠️ youtube.com/watch?v=N7BN--…

Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

Great example demonstrating how to use Hackvertor global variables to store secrets 💎 Two use-cases for this strategy: 1) the project will later be shared and we don't want to leak the secrets 2) we don't want to mix static data (the requests) and dynamic data (the secret)

Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

This behavior (which apparently isn't rare) can be exploited easily with a "Match & Replace" bambda 🛠️🎁 Thanks to ghazi m for sharing his knowledge 🤝

This behavior (which apparently isn't rare) can be exploited easily with a "Match & Replace" bambda 🛠️🎁

Thanks to <a href="/aroly/">ghazi m</a> for sharing his knowledge 🤝
Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

Ever wondered why you NEVER see chunked responses in Burp? 🤔 The answer is simple, default settings hide them! 🫣 Go to "Settings > Network > HTTP > Streaming responses" to make them appear 🔍

Ever wondered why you NEVER see chunked responses in Burp? 🤔

The answer is simple, default settings hide them! 🫣  

Go to "Settings &gt; Network &gt; HTTP &gt; Streaming responses" to make them appear  🔍
Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

Hackvertor now supports tags `<Space/>` and `<newline/>` That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing

Hackvertor now supports tags `&lt;<a href="/space/">Space</a>/&gt;` and `&lt;<a href="/newline/">newline</a>/&gt;`

That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing
Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

The Early Adopter v2025.1 of Burp Suite Pro fixes the bug where the Home and End keys caused the cursor to jump to a different line 🥳 portswigger.net/burp/releases/…

Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

I won't post here anymore. Feel free to join Bluesky or to read the content I post there by simply browsing my profile at bsky.app/profile/master…

Parsia Hakimian (@cryptogangsta) 's Twitter Profile Photo

Web Security Academy ctrl+r, ctrl+shift+r: Send to Repeater, Switch to Repeater. Same with i for Intruder. Courtesy of the wonderful Agarri's Mastering Burp Suite Pro course for drilling that into my mind.

Mastering Burp Suite Pro (@masteringburp) 's Twitter Profile Photo

I just added the 15-minute talk I gave at Tumpicon to the "Freebies" section This talk covers the extensions Piper and Scalpel, and allows users to easily manipulate encrypted data by shuffling blocks around hackademy.agarri.fr/freebies