Set up and optimize Burp Suite to maximize its effectiveness in web application security testing
Explore how Burp Suite can be used to execute various OWASP test cases
Get to grips with the essential features and functionalities of Burp Suite
Purchase of the print or Kindle book includes a free PDF eBook
Description
With its many features, easy-to-use interface, and flexibility, Burp Suite is the top choice for professionals looking to strengthen web application and API security.
This book offers solutions to challenges related to identifying, testing, and exploiting vulnerabilities in web applications and APIs. It provides guidance on identifying security weaknesses in diverse environments by using different test cases. Once you’ve learned how to configure Burp Suite, the book will demonstrate the effective utilization of its tools, such as Live tasks, Scanner, Intruder, Repeater, and Decoder, enabling you to evaluate the security vulnerability of target applications. Additionally, you’ll explore various Burp extensions and the latest features of Burp Suite, including DOM Invader.
By the end of this book, you’ll have acquired the skills needed to confidently use Burp Suite to conduct comprehensive security assessments of web applications and APIs.
Who is this book for?
If you are a beginner- or intermediate-level web security enthusiast, penetration tester, or security consultant preparing to test the security posture of your applications and APIs, this is the book for you.
What you will learn
Perform a wide range of tests, including authentication, authorization, business logic, data validation, and client-side attacks
Use Burp Suite to execute OWASP test cases focused on session management
Conduct Server-Side Request Forgery (SSRF) attacks with Burp Suite
Execute XML External Entity (XXE) attacks and perform Remote Code Execution (RCE) using Burp Suite’s functionalities
Use Burp to help determine security posture of applications using GraphQL
Perform various attacks against JSON Web Tokens (JWTs)
Dr. Wear provides an excellent update from her previous book due to Burp's many upgrades. As someone who performs web application penetration testing daily, Burp Suite is my de facto tool of the trade. Although it is always best to "read the manual," I find I often don't, thus reading this guide greatly helped me understand Burp. This guide provides an excellent manual for all the updated features for Burp Suite and provided me with a great deal of information about Burp Suite I would not have otherwise known. For example, how the resource pool works for throttling Burp. I would like to note though, much of the information is about the Burp Professional edition (which is well worth the money).My only critique is Dr. Wear could provide more detail about how certain payloads work in an application. For example, Dr. Wear uses many intentionally vulnerable applications in her examples. Her example of XSS provides a high-level overview of why XSS works, but for many learners the devil is in the details i.e. which specific parameter is not sanitizing input? As a professional pentester, this is perhaps one of the most important parts of what we do when reporting a vulnerability. Despite this one fault, I found the guide to be informative and detailed on how to use Burp Suite and would definitely recommend it to those who use Burp regularly.
Amazon Verified review
VlsoperNov 03, 2023
5
For web security testers, Burp Suite is the hacker's trusty swiss army knife. This cookbook from veteran Burp expert Dr. Sunny Wear shows readers how to get the most out of this versatile security tool.The book kicks off with recipes for setting up and configuring Burp for maximum effectiveness. Dr. Wear then covers step-by-step how to use Burp to find vulnerabilities like broken auth, insecure session management, injection flaws, and other critical OWASP weaknesses.With over 25 years in web security, Dr. Wear provides practical tips and shortcuts only an insider would know. The cookbook format means you can easily lookup how to pull off advanced attacks like XXE injection or exploit GraphQL APIs.Dr. Wear goes way beyond Burp basics with advanced coverage of automating scans, custom plug-ins, and the latest Burp features like DOM Invader. Her passion for pen testing really comes through in the engaging recipes.For web testers looking to level up their skills, this Burp cookbook should be their go-to guide. Dr. Wear has created the perfect field manual for using Burp to find and exploit holes in web apps and APIs. Her updated Burp cookbook belongs in the backpack of any seasoned security tester.
Amazon Verified review
Larry TrowellNov 02, 2023
5
Burp has been around forever, and recently the interface has gotten a lot more well designed but with the way things have been moved around, it has gotten a little bit confusing. This book can serve as a good intro, as well as a reference for those of us who have been using it for years, but may not day to day and thus may not be familiar with where the current location of specific features are. Overall it is well laid out and there are plenty of areas where it has been useful to me to find where the settings I used to use have moved.
Amazon Verified review
RaymondNov 01, 2023
5
Dr. Wear has some excellent content on Pluralsight which I have learned so much from. This book will get you through the steps to efficiently learn Burp Suite and the basics of web app pentesting. Configuration, suggested plugins, and specific attacks are significantly covered. The book is an excellent primer for entry level web app pentests and CTF competitions as well.
Dr. Sunny Wear is a web security architect and penetration tester. She provides secure coding classes, creates software, and performs penetration testing on web/API and mobile applications. Sunny has more than 25 years of hands-on software programming, architecture, and security experience and holds a Doctor of Science in Cybersecurity. She is a content creator on Pluralsight, with three courses on Burp Suite. She is a published author, a developer of mobile apps such as Burp Tool Buddy, and a content creator on courses related to web security and penetration testing. She regularly speaks and holds classes at security conferences such as Defcon, Hackfest, and BSides.
Where there is an eBook version of a title available, you can buy it from the book details for that title. Add either the standalone eBook or the eBook and print book bundle to your shopping cart. Your eBook will show in your cart as a product on its own. After completing checkout and payment in the normal way, you will receive your receipt on the screen containing a link to a personalised PDF download file. This link will remain active for 30 days. You can download backup copies of the file by logging in to your account at any time.
If you already have Adobe reader installed, then clicking on the link will download and open the PDF file directly. If you don't, then save the PDF file on your machine and download the Reader to view it.
Please Note: Packt eBooks are non-returnable and non-refundable.
Packt eBook and Licensing When you buy an eBook from Packt Publishing, completing your purchase means you accept the terms of our licence agreement. Please read the full text of the agreement. In it we have tried to balance the need for the ebook to be usable for you the reader with our needs to protect the rights of us as Publishers and of our authors. In summary, the agreement says:
You may make copies of your eBook for your own use onto any machine
You may not pass copies of the eBook on to anyone else
How can I make a purchase on your website?
If you want to purchase a video course, eBook or Bundle (Print+eBook) please follow below steps:
Register on our website using your email address and the password.
Search for the title by name or ISBN using the search option.
Select the title you want to purchase.
Choose the format you wish to purchase the title in; if you order the Print Book, you get a free eBook copy of the same title.
Proceed with the checkout process (payment to be made using Credit Card, Debit Cart, or PayPal)
Where can I access support around an eBook?
If you experience a problem with using or installing Adobe Reader, the contact Adobe directly.
To view the errata for the book, see www.packtpub.com/support and view the pages for the title you have.
To view your account details or to download a new copy of the book go to www.packtpub.com/account
Our eBooks are currently available in a variety of formats such as PDF and ePubs. In the future, this may well change with trends and development in technology, but please note that our PDFs are not Adobe eBook Reader format, which has greater restrictions on security.
You will need to use Adobe Reader v9 or later in order to read Packt's PDF eBooks.
What are the benefits of eBooks?
You can get the information you need immediately
You can easily take them with you on a laptop
You can download them an unlimited number of times
You can print them out
They are copy-paste enabled
They are searchable
There is no password protection
They are lower price than print
They save resources and space
What is an eBook?
Packt eBooks are a complete electronic version of the print edition, available in PDF and ePub formats. Every piece of content down to the page numbering is the same. Because we save the costs of printing and shipping the book to you, we are able to offer eBooks at a lower cost than print editions.
When you have purchased an eBook, simply login to your account and click on the link in Your Download Area. We recommend you saving the file to your hard drive before opening it.
For optimal viewing of our eBooks, we recommend you download and install the free Adobe Reader version 9.