Every web app talks to a server. Burp Suite lets you sit in the middle and watch โ or change โ that conversation.
Think of a postal sorting office.
Normally you never see inside the letter. Burp gives you the opening-the-envelope power.
Burp Suite is an intercepting proxy + web security toolkit made by PortSwigger.
Why does it exist? Browsers hide the raw HTTP traffic. Hackers and testers need to see and edit it. Without that, you can only click buttons the developer gave you.
With Burp, you can test what happens when you:
500 to 1That is how real bugs (IDOR, auth bypass, injection) get found.
Without Burp:
[ Browser ] โโโโโโโโโโโโโโโโโโโโโโโโบ [ Server ]
โโโโโโโโโโโโโโโโโโโโโโโโ
With Burp:
[ Browser ] โโโบ [ Burp Proxy ] โโโบ [ Server ]
127.0.0.1:8080
โ
You see it.
You edit it.
You replay it.
โ
[ Browser ] โโโ [ Burp Proxy ] โโโ [ Server ]
Your browser is told: "send everything to 127.0.0.1:8080."
Burp listens there. That is the whole trick.
Each tool has one job. Learn the job, not the buttons.
| Tool | Real-Life Analogy | What It Does |
|---|---|---|
| Proxy | Sorting office | Intercepts and edits live traffic |
| HTTP History | CCTV recording | Logs every request/response that passed |
| Repeater | Practice room | Resend one request again and again with changes |
| Intruder | Key-tester | Automates many requests with changing values |
| Decoder | Translator | Encode/decode Base64, URL, HTML, hex |
| Comparer | Spot-the-difference | Shows differences between two responses |
| Sequencer | Lottery checker | Tests if tokens/session IDs are truly random |
| Target | Map | Shows the site structure Burp has seen |
| Extensions | App store | Add tools from the BApp Store |
Remember this one: Proxy catches โ Repeater experiments โ Intruder automates.
| Feature | Community (Free) | Professional (Paid) |
|---|---|---|
| Proxy, Repeater, Decoder, Comparer | โ | โ |
| Intruder | โ ๏ธ Rate-limited (slow) | โ Full speed |
| Automated vulnerability scanner | โ | โ |
| Collaborator (out-of-band bugs) | โ | โ |
| Save/restore project | โ | โ |
| Extensions (BApp Store) | โ | โ |
Verdict for a student: Community is enough to learn everything. Buy Pro only when you do paid work.
Step 1 โ Install Download Burp Suite Community from PortSwigger's official site. Needs no separate Java โ the installer bundles it.
Step 2 โ Open the embedded browser Go to Proxy โ Intercept โ Open Browser. This is a Chromium browser already wired to Burp. Why use it? Zero proxy setup, zero certificate headaches.
Step 3 โ Turn intercept on Click Intercept is on. Now open any site in that browser. The request freezes inside Burp. Nothing reaches the server yet.
Step 4 โ Read and decide You will see raw HTTP like this:
GET /login HTTP/1.1
Host: example.com
User-Agent: Mozilla/5.0
Cookie: session=abc123
Click Forward to release it, or Drop to kill it.
Step 5 โ Send to Repeater Right-click the request โ Send to Repeater. Edit anything, press Send, read the response. Repeat.
Burp must decrypt HTTPS to show you the content. So it uses its own certificate authority (CA).
http://burpsuite while proxied, download the CA cert, install itWarning: Remove the Burp CA when you finish testing. Anyone with its private key could intercept your traffic.
Never test a site you do not own or have written permission for. Unauthorized testing is a crime, even if you "just looked."
Safe targets:
| Target | Why |
|---|---|
| PortSwigger Web Security Academy | Free, built by the Burp makers, guided labs |
| OWASP Juice Shop | Intentionally vulnerable modern app |
| DVWA | Classic beginner vulnerable app |
| Your own local apps | Full control, zero risk |
| Mistake | Fix |
|---|---|
| Intercept left on, browser "hangs" | Turn intercept off or hit Forward |
| HTTPS sites show cert errors | Use embedded browser or install CA |
| Testing random live sites | Only labs or authorized targets |
| Only clicking, never reading | Read the raw request. Always. |
| Using Intruder on real sites aggressively | Rate-limit, and only with permission |
Burp Suite = intercepting proxy between browser and server
Proxy โ catch and edit live requests
Repeater โ resend one request with changes
Intruder โ automate many requests
Decoder โ encode/decode data
Community โ free, enough to learn everything
Default listener โ 127.0.0.1:8080
Rule #1 โ test only what you are authorized to test
Burp Suite: Intercept and Modify Requests (Hands-On)
TechWithJuned ยท Learn โ Execute โ Build
๐ฌ Questions & Discussion
Have a doubt? Ask below โ no login needed.
Loading comments...