Burp Suite Essentials - Couverture souple

Mahajan, Akash

 
9781783550111: Burp Suite Essentials

Synopsis

If you are interested in learning how to test web applications and the web part of mobile applications using Burp, then this is the book for you. It is specifically designed to meet your needs if you have basic experience in using Burp and are now aiming to become a professional Burp user.

Les informations fournies dans la section « Synopsis » peuvent faire référence à une autre édition de ce titre.

Présentation de l'éditeur

Discover the secrets of web application pentesting using Burp Suite, the best tool for the job

About This Book

  • Acquire and master the skills of a professional Burp user to perform all kinds of security tests on your web applications
  • Integrate and use different components of Burp Suite together such as Proxy, Intruder, Scanner, and Repeater
  • Step-by-step instructions covering the wide range of features of Burp Suite including tips and tricks to use them effectively

Who This Book Is For

If you are interested in learning how to test web applications and the web part of mobile applications using Burp, then this is the book for you. It is specifically designed to meet your needs if you have basic experience in using Burp and are now aiming to become a professional Burp user.

What You Will Learn

  • Get to grips with the user-driven workflow so that you can test any kind of web application
  • Get acquainted with the use of each of the components in Burpa€”Target, Proxy, Intruder, Scanner, and Repeater
  • Search, extract, and match patterns for requests and responses using response extraction rules, URL-matching rules, and Grep - Match
  • Set up and test SSL-enabled applications without any errors
  • Intercept SSL traffic from all kinds of web and mobile applications
  • Develop customized Burp Extensions to suit your needs using Java, Python, and Ruby

In Detail

This book aims to impart the skills of a professional Burp user to empower you to successfully perform various kinds of tests on any web application of your choice. It begins by acquainting you with Burp Suite on various operating systems and showing you how to customize the settings for maximum performance. You will then get to grips with SSH port forwarding and SOCKS-based proxies. You will also get hands-on experience in leveraging the features of Burp tools such as Target, Proxy, Intruder, Scanner, Repeater, Spider, Sequencer, Decoder, and more. You will then move on to searching, extracting, and matching patterns for requests and responses, and you will learn how to work with upstream proxies and SSL certificates. Next, you will dive into the world of Burp Extensions and also learn how to write simple extensions of your own in Java, Python, and Ruby.

As a professional tester, you will need to be able to report your work, safeguard it, and sometimes even extend the tools that you are using; you will learn how to do all this in the concluding chapters of this book.

Biographie de l'auteur

Akash Mahajan

Akash Mahajan is "That Web Application Security Guy." He has more than 10 years of experience in application and network security. Before starting his own company, he was a technical lead for one of the leading American commercial security software companies specializing in endpoint security. He then started working on the security of the web infrastructure for the Government of India. He is the founder and community manager at null - The Open Security Community, where he has made major contributions in making null a national-level group and null Bangalore the biggest and most vibrant chapter. He is currently a chapter leader of Open Web Application Security Project Bangalore (OWASP Bangalore). He is the founder of AppSec Labs, a company focused on application security, where he works with small- and medium-sized companies in securing their web server security, web security, and mobile security, and guiding them to stay secure while being competitive. Currently, his areas of research include DevOps, SecOps, security in SDLC, cloud security, and security awareness through community building. He conducts a lot of training as well, including the extremely popular Xtreme Web Hacking. He was actively involved with the Bangalore Barcamp Planners group and has organized events such as AppJam and MobileCamps all over India, where he has evangelized security to small- and medium-sized enterprises.

Les informations fournies dans la section « A propos du livre » peuvent faire référence à une autre édition de ce titre.