Beginner 5 min read

๐Ÿ•ต๏ธ Burp Suite Overview โ€” Your Web Hacking Workbench

Every web app talks to a server. Burp Suite lets you sit in the middle and watch โ€” or change โ€” that conversation.


๐Ÿง  Easy Analogy (Must Read First!)

Think of a postal sorting office.

  • You write a letter (your browser sends a request)
  • The letter goes to the sorting office (Burp Proxy)
  • You open it, read it, even rewrite it
  • Then you let it go to the real address (the server)
  • The reply comes back through the same office โ€” you can inspect that too

Normally you never see inside the letter. Burp gives you the opening-the-envelope power.


๐Ÿ“˜ What You Will Learn

  • What Burp Suite is and why every web pentester uses it
  • Community vs Professional โ€” what you actually get for free
  • The main tools: Proxy, Repeater, Intruder, Decoder, Comparer
  • How Burp sits between your browser and the server
  • Safe, legal ways to practice

โ“ What Is Burp Suite?

Burp Suite is an intercepting proxy + web security toolkit made by PortSwigger.

Why does it exist? Browsers hide the raw HTTP traffic. Hackers and testers need to see and edit it. Without that, you can only click buttons the developer gave you.

With Burp, you can test what happens when you:

  • Change a price from 500 to 1
  • Swap your user ID for someone else's
  • Send 1000 login attempts
  • Remove a cookie or header

That is how real bugs (IDOR, auth bypass, injection) get found.


๐Ÿ”„ How Burp Works (Flow)

Without Burp:

[ Browser ] โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บ [ Server ]
            โ—„โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€

With Burp:

[ Browser ] โ”€โ”€โ–บ [ Burp Proxy ] โ”€โ”€โ–บ [ Server ]
                127.0.0.1:8080
                     โ”‚
                You see it.
                You edit it.
                You replay it.
                     โ”‚
[ Browser ] โ—„โ”€โ”€ [ Burp Proxy ] โ—„โ”€โ”€ [ Server ]

Your browser is told: "send everything to 127.0.0.1:8080." Burp listens there. That is the whole trick.


๐Ÿงฐ The Main Tools

Each tool has one job. Learn the job, not the buttons.

Tool Real-Life Analogy What It Does
Proxy Sorting office Intercepts and edits live traffic
HTTP History CCTV recording Logs every request/response that passed
Repeater Practice room Resend one request again and again with changes
Intruder Key-tester Automates many requests with changing values
Decoder Translator Encode/decode Base64, URL, HTML, hex
Comparer Spot-the-difference Shows differences between two responses
Sequencer Lottery checker Tests if tokens/session IDs are truly random
Target Map Shows the site structure Burp has seen
Extensions App store Add tools from the BApp Store

Remember this one: Proxy catches โ†’ Repeater experiments โ†’ Intruder automates.


โš–๏ธ Community vs Professional

Feature Community (Free) Professional (Paid)
Proxy, Repeater, Decoder, Comparer โœ… โœ…
Intruder โš ๏ธ Rate-limited (slow) โœ… Full speed
Automated vulnerability scanner โŒ โœ…
Collaborator (out-of-band bugs) โŒ โœ…
Save/restore project โŒ โœ…
Extensions (BApp Store) โœ… โœ…

Verdict for a student: Community is enough to learn everything. Buy Pro only when you do paid work.


๐Ÿš€ Quick Start (5 Steps)

Step 1 โ€” Install Download Burp Suite Community from PortSwigger's official site. Needs no separate Java โ€” the installer bundles it.

Step 2 โ€” Open the embedded browser Go to Proxy โ†’ Intercept โ†’ Open Browser. This is a Chromium browser already wired to Burp. Why use it? Zero proxy setup, zero certificate headaches.

Step 3 โ€” Turn intercept on Click Intercept is on. Now open any site in that browser. The request freezes inside Burp. Nothing reaches the server yet.

Step 4 โ€” Read and decide You will see raw HTTP like this:

GET /login HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0
Cookie: session=abc123

Click Forward to release it, or Drop to kill it.

Step 5 โ€” Send to Repeater Right-click the request โ†’ Send to Repeater. Edit anything, press Send, read the response. Repeat.


๐Ÿ” What About HTTPS?

Burp must decrypt HTTPS to show you the content. So it uses its own certificate authority (CA).

  • Embedded browser โ†’ already trusted, nothing to do
  • Your normal browser โ†’ visit http://burpsuite while proxied, download the CA cert, install it

Warning: Remove the Burp CA when you finish testing. Anyone with its private key could intercept your traffic.


๐ŸŽฏ Where to Practice (Legally)

Never test a site you do not own or have written permission for. Unauthorized testing is a crime, even if you "just looked."

Safe targets:

Target Why
PortSwigger Web Security Academy Free, built by the Burp makers, guided labs
OWASP Juice Shop Intentionally vulnerable modern app
DVWA Classic beginner vulnerable app
Your own local apps Full control, zero risk

โš ๏ธ Common Beginner Mistakes

Mistake Fix
Intercept left on, browser "hangs" Turn intercept off or hit Forward
HTTPS sites show cert errors Use embedded browser or install CA
Testing random live sites Only labs or authorized targets
Only clicking, never reading Read the raw request. Always.
Using Intruder on real sites aggressively Rate-limit, and only with permission

๐ŸŽฏ Final Summary

Burp Suite = intercepting proxy between browser and server
Proxy      โ†’ catch and edit live requests
Repeater   โ†’ resend one request with changes
Intruder   โ†’ automate many requests
Decoder    โ†’ encode/decode data
Community  โ†’ free, enough to learn everything
Default listener โ†’ 127.0.0.1:8080
Rule #1    โ†’ test only what you are authorized to test

๐Ÿ“Œ Next Tutorial

Burp Suite: Intercept and Modify Requests (Hands-On)


TechWithJuned ยท Learn โ†’ Execute โ†’ Build

๐Ÿ’ฌ Questions & Discussion

Have a doubt? Ask below โ€” no login needed.

Loading comments...