· 8 years ago · Dec 07, 2017, 07:12 AM
1Burp Suite
2----------
3Burp or Burp Suite is a graphical tool for testing Web application security. The tool is written in Java and developed by PortSwigger Security.
4Burp Decoder - Free Edition
5
6The tool has two versions: a free version that can be downloaded free of charge (Free Edition) and a full version that can be purchased after a trial period (Professional Edition). It was developed to provide a comprehensive solution for web application security checks. In addition to basic functionality, such as proxy server, scanner and intruder, the tool also contains more advanced options such as a spider, a repeater, a decoder, a comparer, an extender and a sequencer.
7
8
9Anand Prakash
10-------------
11 Bug Bounter, who just knows a chota sa tool which goes by the name of Burp Suite.....
12 He earned 2.2 crores....
13
14 Donald Trump --> fb hack --> Hack By Indian Hacker
15 Hack details ---> Black Market
16 2B dollars
17 Black Listed
18 Non Recognized
19
20Brute Forcing
21-------------
22 To try each and every combination which can be made out of the words.... It is known as Hit & Try Method...
23 A,B,C,D
24 ABCD
25 ABDC
26 ADBC
27 DABC
28 DACB
29 DCAB
30 CDAB
31 ----
32 ----
33 ----
34
35Dictionary Attack
36-----------------
37 I have a text file which contains many many different words. I will try each and every word present in my text file and will check out whether it works or not.
38
39Bug Bounty
40----------
41
42Facebook.com
43 ---> Forget Password
44 ---> phone number
45 ---> OTP
46
47
48
49
50
51OTP
52---
53One Time Password
54
55 4 digits ---> 0000-9999
56 6 digits ---> 000000-999999
57
58 facebook.com
59 twitter.com
60 gmail.com
61 paytm.com
62 olacabs.com
63 uber.com
64
65 beta version
66 m.facebook.com
67 beta.gmail.com
68
69
70DEMO
71====
72
731. Start the XAMPP Server
742. Log in to the DVWA
753. Security "Low"
764. In the left pane --> Brute Force
77 To Set Up The Proxy
78 -------------------
795. Start the Burp Suite
806. Goto "Proxy" Tab ---> "Option"
81 In the first box, it is showing me --> 127.0.0.1:8080
82 I will set the proxy on my web browser with same configurations
837. Open web browser. Goto To "Menu" ----> Options
848. In the left side, goto "Advanced" ----> Goto "Network" ---> "Settings" of the Title "Connection"
859. Check Manual Proxy Configuration
86 127.0.0.1 8080
87 Check Mark the box just below.
8810. Clear the box "No Proxy For"
89
90Brute Force
91-----------
92After setting the proxy.....
93
941. Fill the data with username and password
952. Click on submit button
963. My Burp suite will open up automatically
974. It will glow into Orange....
98 Proxy ---> Intercept
995. Select all the data in the box.....
100 Right Click ---> Send to Intruder
1016. My intruder tab will glow into saffron/orange color... My data has been received by the intruder
1027. Goto "Positions" tab inside "Intruder" tab.
1038. In the "Attack Type" ---> Drop Down Menu---> Select "Cluster Bomb"
1049. In the right side of the screen.... there is a button---> "Clear".... press that button.
10510. Select username and click on add
10611. select password and click on add
10712. Goto "Payloads" tab
10813. Select the payload number 1
109 In the first box----> enter the possible names of the users----> we usually import the dictionary file
11014. Select Payload number 2
111 In the first box enter as many passwords as you can. That is... possible passwords.
11215. In the last tab "Options"
113 Scroll the page to "GREP Match"
114 Clear the whole list/box
115 Add the welcome message/error message in the box here..... Click On "Add"
11616. Say the magic words ----> click on "Start Attack"
117
118
119File Inclusion Vulnerability
120============================
1211. LFI --> Local File Inclusion
1222. RFI --> Remote File Inclusion
123
124
125Command Execution Vulnerability
126===============================
127Enter promo code
128Enter your contact number
129Enter your IP Address
130 | --> Pipe Symbol
131 Output of first command will be the input of second command... After executing first command please, execute my second command
132
133
134
135Welcome to the password protected area admin