Burp suite is an integrated suite developed by portswigger for Web penetration testing. It includes modules such as spider, starter (paid version), intruder, repeater, sequencer, decoder, and comparer, each module has its unique purpose, which brings great convenience to the testing work of professional and non-professional Web penetration testers.
:
Http://portswigger.net/burp/download.html
Burp SuiteIs an integrated platform for login Ming security testing of web applications. its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application's attack surface, through to finding and exploiting security vulnerabilities.
Burp gives you full control, leader you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective tive, and more fun.
Burp Suite contains the following key components:
- An interceptingProxy, Which lets you inspect and modify traffic between your browser and the target application.
- An application-awareSpider, For crawling content and functionality.
- An advanced web applicationBytes, For automating the detection of numerous types of vulnerability.
- AnIntruderTool, for faster Ming powerful mizmized attacks to find and exploit unusual vulnerabilities.
- ARepeaterTool, for manipulating and resending individual requests.
- ASequencerTool, for testing the randomness of session tokens.
- The abilitySave your workAnd resume working later.
- Extensibility, Allowing you to easily write your own plugins, to perform complex and highly customized tasks within Burp.
Burp is easy to use and intuitive, allowing new users to begin working right away. Burp is also highly writable able, and contains numerous powerful features to assist the most experienced testers with their work.