Skip to content

falasi/BurpCertifiedPractitioner

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

20 Commits
 
 
 
 
 
 

Repository files navigation

Resources

To do:

  • Add Burp scan Configs.
  • Add Cyberchef Recipes.
  • Add Payloads.

Default Creds: wiener:peter

Extensions:

  • Turbo Intruder
  • HTTP Request Smuggler
  • JS Miner
  • Flow / Logger++
  • Active Scan++
  • Hackvertor
  • Auth Analyzer
  • Upload Scanner

Tools:

Portswigger Cheatsheets:

Stages and what to look for. Credit to Micah Van Deusen writeup

Category Stage 1 Stage 2 Stage 3
SQL Injection ✔️ ✔️
Cross-site scripting ✔️ ✔️
Cross-site request forgery (CSRF) ✔️ ✔️
Clickjacking ✔️ ✔️
DOM-based vulnerabilities ✔️ ✔️
Cross-origin resource sharing (CORS) ✔️ ✔️
XML external entity (XXE) injection ✔️
Server-side request forgery (SSRF) ✔️
HTTP request smuggling ✔️ ✔️
OS command injection ✔️
Server-side template injection ✔️
Directory traversal ✔️
Access control vulnerabilities ✔️ ✔️
Authentication ✔️ ✔️
Web cache poisoning ✔️ ✔️
Insecure deserialization ✔️
HTTP Host header attacks ✔️ ✔️
OAuth authentication ✔️ ✔️
File upload vulnerabilities ✔️
JWT ✔️ ✔️

Common Hackverter tags:

  • <@urlencode><@/urlencode>
  • <@urlencode_all><@/urlencode_all>
  • <@d_url><@/d_url>

Learning:

Port Swigger all materials

About

Wordlists, POCs for Burp Certified Practitioner

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published