Burp Suite Essentials
暫譯: Burp Suite 基礎知識
Akash Mahajan
- 出版商: Packt Publishing
- 出版日期: 2014-11-30
- 售價: $1,470
- 貴賓價: 9.5 折 $1,397
- 語言: 英文
- 頁數: 144
- 裝訂: Paperback
- ISBN: 1783550112
- ISBN-13: 9781783550111
海外代購書籍(需單獨結帳)
相關主題
商品描述
About This Book
- Acquire and master the skills of a professional Burp user to perform all kinds of security tests on your web applications
- Integrate and use different components of Burp Suite together such as Proxy, Intruder, Scanner, and Repeater
- Step-by-step instructions covering the wide range of features of Burp Suite including tips and tricks to use them effectively
Who This Book Is For
If you are interested in learning how to test web applications and the web part of mobile applications using Burp, then this is the book for you. It is specifically designed to meet your needs if you have basic experience in using Burp and are now aiming to become a professional Burp user.
What You Will Learn
- Get to grips with the user-driven workflow so that you can test any kind of web application
- Get acquainted with the use of each of the components in Burpa”Target, Proxy, Intruder, Scanner, and Repeater
- Search, extract, and match patterns for requests and responses using response extraction rules, URL-matching rules, and Grep - Match
- Set up and test SSL-enabled applications without any errors
- Intercept SSL traffic from all kinds of web and mobile applications
- Develop customized Burp Extensions to suit your needs using Java, Python, and Ruby
In Detail
This book aims to impart the skills of a professional Burp user to empower you to successfully perform various kinds of tests on any web application of your choice. It begins by acquainting you with Burp Suite on various operating systems and showing you how to customize the settings for maximum performance. You will then get to grips with SSH port forwarding and SOCKS-based proxies. You will also get hands-on experience in leveraging the features of Burp tools such as Target, Proxy, Intruder, Scanner, Repeater, Spider, Sequencer, Decoder, and more. You will then move on to searching, extracting, and matching patterns for requests and responses, and you will learn how to work with upstream proxies and SSL certificates. Next, you will dive into the world of Burp Extensions and also learn how to write simple extensions of your own in Java, Python, and Ruby.
As a professional tester, you will need to be able to report your work, safeguard it, and sometimes even extend the tools that you are using; you will learn how to do all this in the concluding chapters of this book.
商品描述(中文翻譯)
揭開使用 Burp Suite 進行網頁應用程式滲透測試的秘密,這是最佳的工具
本書介紹
- 獲得並掌握專業 Burp 使用者的技能,以對您的網頁應用程式進行各種安全測試
- 整合並使用 Burp Suite 的不同組件,如 Proxy、Intruder、Scanner 和 Repeater
- 逐步指導涵蓋 Burp Suite 的廣泛功能,包括有效使用它們的技巧和竅門
本書適合誰
如果您有興趣學習如何使用 Burp 測試網頁應用程式及行動應用程式的網頁部分,那麼這本書就是為您而設。它專門設計以滿足您的需求,特別是如果您已經具備使用 Burp 的基本經驗,並希望成為專業的 Burp 使用者。
您將學到什麼
- 掌握以使用者為中心的工作流程,以便您可以測試任何類型的網頁應用程式
- 熟悉 Burp 的每個組件的使用,包括 Target、Proxy、Intruder、Scanner 和 Repeater
- 使用回應提取規則、URL 匹配規則和 Grep - Match 搜尋、提取和匹配請求和回應的模式
- 設置並測試啟用 SSL 的應用程式,確保無錯誤
- 攔截各類網頁和行動應用程式的 SSL 流量
- 使用 Java、Python 和 Ruby 開發自訂的 Burp 擴展以滿足您的需求
詳細內容
本書旨在傳授專業 Burp 使用者的技能,使您能夠成功對任何您選擇的網頁應用程式進行各種測試。它首先讓您熟悉在各種作業系統上使用 Burp Suite,並展示如何自訂設置以達到最佳性能。接著,您將掌握 SSH 端口轉發和基於 SOCKS 的代理。您還將獲得利用 Burp 工具的功能的實作經驗,包括 Target、Proxy、Intruder、Scanner、Repeater、Spider、Sequencer、Decoder 等等。然後,您將進一步學習搜尋、提取和匹配請求和回應的模式,並學習如何處理上游代理和 SSL 證書。接下來,您將深入了解 Burp 擴展的世界,並學習如何使用 Java、Python 和 Ruby 編寫自己的簡單擴展。
作為一名專業測試者,您需要能夠報告您的工作、保護它,有時甚至擴展您正在使用的工具;您將在本書的結尾章節中學習如何做到這一切。