Mastering Burp Suite Pro

1.2K posts

Mastering Burp Suite Pro

Mastering Burp Suite Pro

@MasteringBurp

Tips and tricks for Burp Suite Pro Managed by @Agarri_FR | Not affiliated with @Portswigger More free resources at https://t.co/MWqXmV66lr

Katılım Eylül 2020
0 Takip Edilen16.2K Takipçiler
Mastering Burp Suite Pro retweetledi
Nicolas Grégoire
Nicolas Grégoire@Agarri_FR·
Come to Roma 🇮🇹 in September and attend the only in-person public training session I'll give in 2026! 👨‍🏫 And if you like camping with other hackers (as I do), stay over the weekend for the 3-day long RomHack Camp 🏕️
Cyber Saiyan | RomHack Conference, Training, Camp@cybersaiyanIT

RomHack Training registration is officially open. Join us in Rome from September 28 to October 1 for six intensive technical tracks led by industry experts: Full details and registration: romhack.training #RomHack2026 #RomHackTraining

English
0
1
7
3.3K
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
An interesting piece of trivia: the search bar works on custom columns (the ones created via bambdas) and also on hidden ones (whatever they are custom or not)
English
0
0
0
492
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
Since EA 2026.2, there's a a search bar in Proxy History and it doesn't work exactly like the usual display filter. Let me explain... - the filter searches in requests, responses and notes - the search bar looks for the keyword in the table of entries itself
English
1
0
4
1.1K
Mastering Burp Suite Pro retweetledi
Nicolas Grégoire
Nicolas Grégoire@Agarri_FR·
The 2026 online public sessions of my "Mastering Burp Suite Pro" course have been published - March 24th to 27th, in French 🇫🇷 - April 14th to 17th, in English 🇬🇧 hackademy.agarri.fr/2026 PS: ping me if you'd like to temporarily block a seat or are looking for a 10% coupon 🎁
English
0
6
24
4.9K
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
I just added the 15-minute talk I gave at Tumpicon to the "Freebies" section This talk covers the extensions Piper and Scalpel, and allows users to easily manipulate encrypted data by shuffling blocks around hackademy.agarri.fr/freebies
English
0
20
96
8.8K
Mastering Burp Suite Pro retweetledi
Web Security Academy
Web Security Academy@WebSecAcademy·
What's your best @Burp_Suite tip or trick and where did you learn it?
English
7
5
50
10.2K
Parsia Hakimian
Parsia Hakimian@CryptoGangsta·
@WebSecAcademy ctrl+r, ctrl+shift+r: Send to Repeater, Switch to Repeater. Same with i for Intruder. Courtesy of the wonderful Agarri's @MasteringBurp course for drilling that into my mind.
English
1
0
10
1.3K
Web Security Academy
Web Security Academy@WebSecAcademy·
What are your favorite Burp Suite hotkeys and what do they do?
Web Security Academy tweet media
English
3
1
20
3.5K
Mastering Burp Suite Pro retweetledi
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
If you never used the Piper extension, I recommend to watch the 4-minute demo I gave last year during my talk at @NorthSec_io 🛠️ youtube.com/watch?v=N7BN--…
YouTube video
YouTube
doomerhunter (Victor Poucheret)@DoomerOutrun

@CristiVlad25 Basically allows you to execute **any** tool/command on **any** part of an HTTP request/réponse. It can pipe tools together as well as automatically execute pipelines. You can even launch GUI tools such as meld for easy diffing @Agarri_FR mentioned it a while ago and it's awesome

English
2
19
84
15.4K
Mastering Burp Suite Pro retweetledi
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
Hackvertor now supports tags `<@space/>` and `<@newline/>` That doesn't look like a game-changer, but it's incredibly useful when you want to avoid that these raw characters break Burp's HTTP parsing
Mastering Burp Suite Pro tweet media
English
2
11
71
8.2K
Mastering Burp Suite Pro
Mastering Burp Suite Pro@MasteringBurp·
@irsdl @space @newline Same, I never use "URL-encode as you type", among other reasons because pasting != typing And I use the urlencode tag a lot, let's see if that changes now that we have these two new tags
English
1
0
2
300
Soroush Dalili
Soroush Dalili@irsdl·
@MasteringBurp @space @newline Do you mean the one that url encode as you type or this a different feature? Because that's the one I never use the type and encode. I prefer to have url encode tags around stuff and you can have a hv custom tag to handle different cases or multiple params.
English
1
0
0
136
Soroush Dalili
Soroush Dalili@irsdl·
@MasteringBurp @space @newline I usually turn of the auto content length update and that solves the issue. Of course if I then need to fiddle with the body, I need to cheat more!
English
1
0
6
467