Burp Suite Cheat Sheet
Covers Burp Suite's core web application testing workflow including proxy setup, Repeater, Intruder, and scanning best practices.
Core Tools
The main components of Burp Suite used in a typical assessment.
- Proxy- Intercepts and modifies HTTP/S traffic between browser and server
- Repeater- Manually resend and edit individual requests to test behavior
- Intruder- Automates sending many requests with varying payloads (fuzzing, brute force)
- Scanner- Automated vulnerability scanning (Burp Suite Pro only)
- Decoder- Encode/decode data (Base64, URL, Hex, HTML entities)
- Comparer- Diff two requests/responses to spot differences
- Target/Site map- Tracks discovered site structure and endpoints
Proxy Setup Workflow
Steps to intercept browser traffic through Burp.
- 1. Configure browser proxy- Point browser to 127.0.0.1:8080 (Burp's default listener)
- 2. Install CA certificate- Visit http://burp on the proxied browser and install cert to inspect HTTPS
- 3. Enable/disable intercept- Toggle 'Intercept is on' in the Proxy tab to hold or forward requests
- 4. Send to Repeater- Right-click a captured request to send it for manual replay/editing
Intruder Attack Types
Payload position strategies for automated request fuzzing.
Sniper # One payload set, cycles through each § position § one at a timeBattering ram # One payload set, same value inserted in all positions simultaneouslyPitchfork # Multiple payload sets, iterated in parallel (position 1 <-> set 1)Cluster bomb # Multiple payload sets, all combinations tested (position1 x position2)
Common Manual Tests via Repeater
Typical checks performed by editing and resending requests.
- Auth bypass- Remove/modify session tokens or headers to test access control
- IDOR- Change object IDs in requests to access other users' data
- Injection payloads- Insert SQLi/XSS strings into parameters and observe responses
- HTTP method tampering- Swap GET/POST/PUT to test for inconsistent server-side checks
Session Handling Rules & Macros
Configure Burp to auto-refresh CSRF tokens or re-authenticate mid-scan by recording a macro and attaching it as a session handling rule.
Project options > Sessions > Macros > Add - Record a login request sequence (POST /login, then GET /dashboard) - Configure item: extract the response's csrf_token parameter as a macro variableProject options > Sessions > Session Handling Rules > Add - Scope: Tools = Proxy, Repeater, Intruder, Scanner - Rule actions: 1. Run macro "Login" (re-authenticates when session expires) 2. Update a specific value: csrf_token -> from macro's extracted value - URL scope: restrict to the target host so the macro doesn't fire on out-of-scope traffic# Result: Intruder/Scanner runs survive session expiry and CSRF token rotation# without manually re-capturing a fresh request every few minutes.
Burp Collaborator for Blind Vulnerabilities
Detect out-of-band interactions (blind SSRF, blind XXE, blind RCE) by injecting a unique Collaborator payload and polling for callbacks.
1. Burp > Collaborator client > Copy a unique payload, e.g.: a1b2c3d4e5.oastify.com2. Inject it where the app might make an outbound request or resolve an entity: - SSRF: POST /fetch-avatar {"url": "http://a1b2c3d4e5.oastify.com/x"} - XXE: <!DOCTYPE foo [ <!ENTITY x SYSTEM "http://a1b2c3d4e5.oastify.com/x"> ]> - Blind command injection: `; nslookup a1b2c3d4e5.oastify.com`3. Poll Collaborator client (or let Burp auto-poll during a scan) for DNS/HTTP/SMTP interactions -- any hit confirms the app reached out, even with zero visible response difference in the original request.# Self-hosted alternative for isolated/airgapped engagements: run your own# Collaborator server and point Burp at it via Project options > Misc.
Notable BApp Store Extensions
Community extensions (Extender > BApp Store) that extend Burp beyond core functionality for specific test types.
- Autorize- Automates authorization testing by replaying requests with a lower-privileged session's cookies to catch IDOR/broken access control
- Turbo Intruder- Python-scriptable high-throughput request engine for race conditions and large-scale fuzzing beyond stock Intruder's rate
- JSON Web Tokens- Decodes, edits, and re-signs JWTs inline, including alg=none and key-confusion attack helpers
- Param Miner- Discovers hidden/unlinked parameters and headers via intelligent guessing, useful for cache poisoning and hidden functionality
- Logger++- Extended, filterable logging across all Burp tools with CSV export for later correlation
- GraphQL Raider- Introspection-aware GraphQL query manipulation and batching attack support
- Software Vulnerability Scanner- Cross-references response headers/banners against known-CVE fingerprints
Turbo Intruder: Race Condition PoC
Turbo Intruder's Python script format for firing near-simultaneous requests to test single-use-token or limited-use-resource race conditions.
def queueRequests(target, wordlists): engine = RequestEngine( endpoint=target.endpoint, concurrentConnections=20, engine=Engine.BURP2 ) # Fire the same redemption request 20 times concurrently for i in range(20): engine.queue(target.req, gate='race1') # Release all queued requests at once to hit the race window engine.openGate('race1')def handleResponse(req, interesting): table.add(req) # Expect only one 200 (success); duplicates indicate a TOCTOU vulnerability if 'redeemed' in req.response.lower(): print('Possible double-redeem: ' + str(req.response))
Advanced Scope & Automation Workflow
Practices for keeping large or long-running engagements organized and reproducible.
- Target > Scope include/exclude rules- Use regex-based advanced scope to permit staging subdomains while excluding third-party CDNs from accidental testing
- Suite-wide 'in-scope only' filters- Enable across Proxy history, Logger++, and Scanner so noise from ads/analytics never pollutes findings
- Burp REST/Montoya extension API- Drive scans and pull results programmatically for CI-integrated authorized testing pipelines
- Save/restore project state- .burp project files snapshot scope, history, and issues, allowing multi-day engagements to resume exactly where you left off
- Content discovery with custom wordlists- Feed target-specific terms (from JS bundles, error messages) into Intruder rather than relying only on generic wordlists
Use 'Match and Replace' rules in the Proxy settings to automatically strip or rewrite headers (like Cache-Control or CSP) on the fly across every request, saving repetitive manual edits during long test sessions.