burpsuite

**- Burp Sequencer

Importing certificate in firefox

https://portswigger.net/burp/documentation/desktop/external-browser-config/certificate/ca-cert-firefox

  1. http://burpsuite/
  2. Authorities > Import

Usage in macos and firefox

Use https://addons.mozilla.org/en-US/firefox/addon/foxyproxy-standard/

Download

Using burploader in apple m1

cd ~/dev/Burp\ Suite/
"/opt/homebrew/Cellar/openjdk/24.0.1/libexec/openjdk.jdk/Contents/Home/bin/java" "--add-opens=java.desktop/javax.swing=ALL-UNNAMED" "--add-opens=java.base/java.lang=ALL-UNNAMED" "--add-opens=java.base/jdk.internal.org.objectweb.asm=ALL-UNNAMED" "--add-opens=java.base/jdk.internal.org.objectweb.asm.tree=ALL-UNNAMED" "--add-opens=java.base/jdk.internal.org.objectweb.asm.Opcodes=ALL-UNNAMED" "-javaagent:burploader.jar" "-noverify" "-jar" "/Applications/Burp Suite Professional.app/Contents/Resources/app/burpsuite_pro.jar"

The Burp Suite is a highly recognized, integrated platform and graphical tool used extensively for performing security testing of web applications. Developed by PortSwigger Web Security, it is often classified as an Interception Proxy.

Burp Suite is implemented as a Java-based Web Penetration Testing framework and is used by security professionals to verify attack vectors and identify vulnerabilities affecting web applications. Its various tools are designed to work seamlessly together to support the entire testing process, from initial mapping and analysis to finding and exploiting security vulnerabilities.

🛠️ Core Capabilities and Built-in Tools

Burp Suite includes several built-in tools that facilitate comprehensive security auditing:

💥 Use Cases and Attacks Exploited with Burp Suite

Attackers and penetration testers rely on Burp Suite to execute or aid in various high-impact attacks:

💻 AI Integration

The functionality of Burp Suite has been extended through integration with AI via a specific tool: