home/toolvault/web app testing/burp-suite

Burp Suite //

Web App Testingintercept proxy

Burp sits between your browser and the web app, letting you see and modify every request. It's the #1 tool of web testers and bug bounty hunters.

difficulty Β· intermediate
20 min
time to first win
5
guided steps
0
students started here*

HOW TO USE BURP SUITE

Follow the steps β€” click any step card to replay the terminal demo from that point. Everything runs in a lab you control.

burp-suite β€” guided lab session
static view
step 01

Route your browser through Burp

FoxyProxy β†’ 127.0.0.1:8080

Install Burp's CA certificate or HTTPS sites will scream.

step 02

Intercept a login attempt

Proxy β†’ Intercept on β†’ submit form

See exactly what the app sends. Edit anything, forward, watch the result.

step 03

Replay it your way

right-click β†’ Send to Repeater (Ctrl+R)

Repeater is where 90% of manual testing happens.

step 04

Fuzz a parameter

Send to Intruder β†’ mark Β§paramΒ§ β†’ rockyou.txt

CE throttles speed; the workflow is what matters. Try ffuf for speed.

step 05

Map the app

Target β†’ Site map

Passive crawl as you browse = your attack surface inventory.

THE WORKFLOW AT A GLANCE

🌐
Browse
through Burp
πŸ•ΈοΈ
Map
endpoints & params
βœ‚οΈ
Intercept
see raw requests
πŸ”
Repeater
poke & observe
πŸ’₯
Intruder
automated fuzz
LEARNING CURVE
intermediate β€” 20 min to first win

FLAGS & SUPER-MOVES

Proxyintercept & history
Repeatermanual replay lab
Intruderpayload fuzzing
Decoderencode/decode quickly
Comparerdiff two responses
ExtensionsBApp store toys: Autorize…

PRO TIPS

01

Scope the target (Target β†’ Scope) so you only attack what you're allowed.

Scope the target (Target β†’ Scope) so you only attack what you're allowed.

02

Match & replace rules auto-ride sessions

Match & replace rules auto-ride sessions: swap logged-out cookies for admin ones, watch access control break.

03

PortSwigger Academy labs assume Burp workflows β€” do them in order.

PortSwigger Academy labs assume Burp workflows β€” do them in order.

04

Hotkeys win

Hotkeys win: Ctrl+R repeater, Ctrl+I interceptor, Ctrl+Shift+T new tab.

βš–οΈ

Golden rule

Use Burp Suite only on systems you own or have written permission to test. Your lab: Kali + Metasploitable2, DVWA, TryHackMe & HackTheBox β€” plenty of legal targets, zero risk.

KEEP DIGGING

CYBER//ZERO ToolVault
Animated deep-dives on every tool in the guide.
✍️ Author LDM · ldmhub4u@gmail.com
full guide v1 Β· v2 immersive Β· latest news
Made for learners, everywhere Β· 2026
*plausibly. verify commands with official docs.