Recon with Burp
Burp Suite's reconnaissance tools are essential for mapping web applications and uncovering hidden endpoints during penetration testing. By systematically analyzing HTTP traffic, leveraging automated tools, and manually testing endpoints, red teams can build a comprehensive understanding of the target's attack surface. This section covers advanced techniques for reconnaissance using Burp Suite's core tools.
Mapping the Application with the Scanner¶
Burp Scanner can automate the discovery of endpoints and vulnerabilities by crawling the application's structure. While primarily designed for vulnerability detection, its crawling capabilities help map the attack surface.
Steps:
1. Set the target URL in the Scanner's Target tab.
2. Configure the Scope to include relevant subdomains and endpoints.
3. Run the scan; Burp will intercept and analyze traffic, identifying endpoints, forms, and potential vulnerabilities.
Example:
Note: The Scanner may miss endpoints requiring authentication or dynamic parameters. Combine it with manual testing for completeness.
Identifying Hidden Endpoints with Intruder¶
Burp Intruder is ideal for fuzzing endpoints, headers, and parameters to uncover hidden or misconfigured paths.
Steps:
1. Intercept a request in the Proxy tab.
2. Send it to Repeater to analyze the response.
3. Use Intruder to replace a parameter (e.g., /login) with a payload list containing potential endpoints (e.g., /admin, /backup, /config).
Example:
Payloads (Intruder):
Attack Type:
- ** Sniper:** Test one payload at a time.
- Cluster Bomb: Test all payloads simultaneously.
Tip: Use common directory structures (e.g., /var, /tmp, /logs) or leaked paths from source code for payloads.
Manual Testing with Repeater¶
The Repeater tool allows precise modification of requests to test endpoints and observe responses.
Steps:
1. Intercept a request in the Proxy tab.
2. Send it to Repeater.
3. Modify parameters, headers, or URLs to simulate different scenarios (e.g., adding ?debug=1 to a query string).
Example:
Observation:
- A 200 OK response with unexpected content (e.g., admin panel HTML) indicates a hidden endpoint.
- A 403 Forbidden response may suggest misconfigured access controls.
Leveraging the Proxy for Traffic Analysis¶
The Proxy tab is the primary tool for intercepting and analyzing all HTTP traffic.
Steps:
1. Enable interception in the Proxy tab.
2. Browse the target application to capture requests.
3. Analyze the Site Map (under the Scanner tab) to identify all discovered endpoints.
Example:
Key Insight:
- Use the Scope settings to filter traffic to relevant subdomains.
- Look for unusual endpoints (e.g., /api/v1/ or /swagger-ui/) that may indicate internal services.
Key takeaways¶
- Use Burp Scanner to automate endpoint discovery and vulnerability detection.
- Intruder is critical for fuzzing endpoints and uncovering hidden paths.
- Repeater enables precise manual testing of suspicious endpoints.
- The Proxy tab is indispensable for intercepting and analyzing all traffic during reconnaissance.
- Always refine Scope settings to focus on relevant subdomains and paths.