Chuyển đến nội dung chính

Lesson 15: Web Application Testing — Burp Suite and OWASP ZAP

Intercepting proxy, active/passive scanning, Intruder/Repeater, ZAP automation, comparison of Burp Suite Pro vs OWASP ZAP.

🔒 DevSecOps — Lesson 15 Lesson 15: Web Application Testing — Burp Suite and OWASP ZAP

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 3: Pentest Foundations — Process and Methodology

xdev.asia

1. Intercepting Proxy — Concept

Intercepting Proxy Workflow:

  Browser ──────▶ Proxy ──────▶ Web Server
                   │
            ┌──────┴──────┐
            │  Intercept   │
            │  Modify      │
            │  Replay      │
            │  Record      │
            └─────────────┘

Why use a proxy?
  ├── Inspect all HTTP/HTTPS traffic
  ├── Modify requests before they reach server
  ├── Modify responses before they reach browser
  ├── Automate testing (fuzzing, scanning)
  └── Record traffic for analysis and reporting

2. Burp Suite — Setup and Configuration

Burp Suite Editions:
  Community (Free):
    ├── Proxy, Repeater, Decoder, Comparer
    ├── Intruder (rate-limited)
    └── No Scanner, no saving

  Professional ($449/year):
    ├── Full Scanner (active + passive)
    ├── Intruder (no rate limit)
    ├── Collaborator (OOB testing)
    ├── Extensions (BApp Store)
    └── Save/restore projects

  Enterprise (server-based):
    └── CI/CD integration, scheduled scans

Setup:
  1. Download from portswigger.net
  2. Configure proxy: 127.0.0.1:8080 
  3. Install CA certificate in browser
  4. Configure browser to use proxy
  5. Turn on Intercept → browse target
Essential Burp Extensions (BApp Store):
  ├── Active Scan++ : Enhanced scanner checks
  ├── Autorize      : Authorization testing
  ├── Logger++      : Enhanced logging
  ├── JSON Beautifier: Format JSON in Proxy
  ├── Param Miner   : Hidden parameter discovery
  ├── Turbo Intruder: Fast, scriptable Intruder
  ├── JWT Editor    : JWT manipulation
  ├── Hackvertor   : Encoding/decoding tags
  └── Upload Scanner: File upload testing

3. Burp Proxy & Repeater

Proxy Tab Workflow:
  1. Intercept ON → browse target application
  2. Examine each request:
     - Check parameters, cookies, headers
     - Look for auth tokens, session IDs
  3. Forward, Drop, or send to Repeater/Intruder
  4. Review HTTP history for all captured traffic

Repeater — Manual Testing:
  1. Send interesting request to Repeater (Ctrl+R)
  2. Modify parameters one at a time
  3. Send and analyze response
  4. Common tests:
     - Change user ID → IDOR
     - Add admin=true → privilege escalation
     - SQL payloads in parameters → injection
     - XSS payloads in input fields
     - Remove auth headers → access control
### Example: Testing IDOR in Repeater

# Original request:
GET /api/v1/users/123/orders HTTP/2
Host: api.example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...
Cookie: session=abc123

# Modified — change user ID:
GET /api/v1/users/456/orders HTTP/2
Host: api.example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...
Cookie: session=abc123

# If response 200 with user 456's data → IDOR confirmed!

### Example: Testing parameter pollution
POST /api/v1/transfer HTTP/2
Host: api.example.com
Content-Type: application/json
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...

{"from": "123", "to": "456", "amount": 100, "amount": -100}
# Some parsers take last value → negative transfer

4. Burp Intruder — Automated Attack

Intruder Attack Types:

  Sniper:        One payload position at a time
  Battering Ram:  Same payload in all positions
  Pitchfork:     Different payloads, synchronized
  Cluster Bomb:  All combinations of payloads

Example: Brute-force login
  POST /login
  username=§admin§&password=§P@ssw0rd§

  Attack Type: Cluster Bomb
  Position 1 (username): admin, root, administrator
  Position 2 (password): wordlist (rockyou-top-1000.txt)

  Total requests: 3 × 1000 = 3000

Analyzing Results:
  - Sort by Status Code (200 vs 401)
  - Sort by Response Length (different = interesting)
  - Sort by Response Time (longer = potential timing attack)
  - Grep for keywords ("success", "welcome", "invalid")
Turbo Intruder Script (Python/Jython):
# For high-speed attacks (bypassing rate limits)

def queueRequests(target, wordlists):
    engine = RequestEngine(
        endpoint=target.endpoint,
        concurrentConnections=5,
        requestsPerConnection=100,
        pipeline=True
    )
    
    for word in open('/usr/share/wordlists/common.txt'):
        engine.queue(target.req, word.rstrip())

def handleResponse(req, interesting):
    if req.status == 200:
        table.add(req)
    # Race condition testing:
    # if req.status != 429:
    #     table.add(req)

5. Burp Scanner (Pro)

Scanner Modes:
  Passive Scan:
    ├── Analyzes existing traffic (no extra requests)
    ├── Finds: cookies without flags, info disclosure
    ├── Missing headers, sensitive data in URLs
    └── Always running in background

  Active Scan:
    ├── Sends additional requests to test vulnerabilities
    ├── Finds: SQLi, XSS, SSRF, command injection
    ├── Can be noisy (triggers WAF/IDS)
    └── Right-click → "Scan" on specific requests

Scan Configuration:
  ├── Audit items: Select which checks to run
  ├── Crawl: Configure crawl depth and scope
  ├── Handling: Login macros, session handling rules
  └── Reporting: Generate HTML/XML reports

6. OWASP ZAP — Free Alternative

# --- OWASP ZAP Installation ---

# Docker (recommended)
docker pull ghcr.io/zaproxy/zaproxy:stable

# --- ZAP CLI Commands ---

# Quick scan (spider + active scan)
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
  zap-full-scan.py -t https://example.com \
  -r zap_report.html

# API scan (OpenAPI/Swagger)
docker run --rm -v $(pwd):/zap/wrk ghcr.io/zaproxy/zaproxy:stable \
  zap-api-scan.py -t https://example.com/openapi.json \
  -f openapi \
  -r api_report.html

# Baseline scan (passive only — safe for production)
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
  zap-baseline.py -t https://example.com \
  -r baseline_report.html

# --- ZAP with authentication ---
docker run --rm -v $(pwd):/zap/wrk ghcr.io/zaproxy/zaproxy:stable \
  zap-full-scan.py -t https://example.com \
  -r auth_report.html \
  -z "-config auth.loginurl=https://example.com/login \
      -config auth.username=test \
      -config auth.password=Test123!"
# --- ZAP Automation Framework ---
# zap-automation.yaml

env:
  contexts:
    - name: "Example App"
      urls:
        - "https://example.com"
      includePaths:
        - "https://example.com/.*"
      excludePaths:
        - "https://example.com/logout.*"
      authentication:
        method: "form"
        parameters:
          loginPageUrl: "https://example.com/login"
          loginRequestUrl: "https://example.com/api/auth/login"
          loginRequestBody: "username={%username%}&password={%password%}"
        verification:
          method: "response"
          loggedInRegex: "\\Qdashboard\\E"
      users:
        - name: "test-user"
          credentials:
            username: "testuser"
            password: "TestPassword123!"

jobs:
  - type: spider
    parameters:
      maxDuration: 5
      maxDepth: 5
      maxChildren: 10

  - type: spiderAjax
    parameters:
      maxDuration: 5

  - type: passiveScan-wait
    parameters:
      maxDuration: 5

  - type: activeScan
    parameters:
      maxRuleDurationInMins: 5
      maxScanDurationInMins: 30
      policy: "Default Policy"

  - type: report
    parameters:
      template: "traditional-html"
      reportDir: "/zap/wrk"
      reportFile: "zap-scan-report"
    risks:
      - high
      - medium
      - low

7. ZAP in CI/CD Pipeline

# .github/workflows/security-scan.yml

name: DAST Security Scan

on:
  push:
    branches: [main, develop]
  schedule:
    - cron: '0 2 * * 1'  # Weekly Monday 2AM

jobs:
  zap-scan:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: Start application
        run: |
          docker-compose up -d
          sleep 30  # Wait for app to be ready

      - name: ZAP Baseline Scan
        uses: zaproxy/[email protected]
        with:
          target: 'http://localhost:3000'
          rules_file_name: 'zap-rules.tsv'
          cmd_options: '-a'

      - name: ZAP Full Scan
        if: github.ref == 'refs/heads/main'
        uses: zaproxy/[email protected]
        with:
          target: 'http://localhost:3000'
          rules_file_name: 'zap-rules.tsv'

      - name: Upload ZAP Report
        uses: actions/upload-artifact@v4
        if: always()
        with:
          name: zap-report
          path: report_html.html
# zap-rules.tsv — Customize alert handling
# WARN = report but don't fail
# FAIL = fail the CI pipeline
# IGNORE = skip this check

10011	WARN	(Cookie Without Secure Flag)
10015	FAIL	(Incomplete or No Cache-control)
10020	FAIL	(X-Frame-Options Header Missing)
10021	FAIL	(X-Content-Type-Options Missing)
10038	FAIL	(Content Security Policy Missing)
10098	WARN	(Cross-Domain Misconfiguration)
40012	FAIL	(Cross Site Scripting Reflected)
40014	FAIL	(Cross Site Scripting Persistent)
40018	FAIL	(SQL Injection)
90033	FAIL	(Loosely Scoped Cookie)

8. Compare Burp Suite Pro vs OWASP ZAP

FeatureBurp Suite ProOWASP ZAP
Price$449/yearFree / Open Source_
ScannerIndustry-leading_Good, improve_
Extensions_BApp Store (rich)_Marketplace (growing)
IntruderFull-speedFuzzer (basic)
CollaboratorBuilt-in OOB server_No equivalent_
CI/CDEnterprise editionNative (GitHub Actions)
APIREST API (Enterprise)Full REST API (free)
Learning_PortSwigger AcademyCommunity docs_
Best for_Professional pentesters_DevSecOps, automation

9. Summary

  • Burp Suite: Industry standard — Proxy, Repeater, Intruder, Scanner
  • OWASP ZAP: Free alternative — excellent for CI/CD automation
  • Proxy workflow: Intercept → Analyze → Modify → Replay → Report
  • CI/CD integration: ZAP GitHub Actions for automated DAST
  • Best practice: Use both — ZAP for automation, Burp for manual testing

The next article will delve into Exploitation Frameworks — Metasploit.