1. Intercepting Proxy — Concept
Intercepting Proxy Workflow:
Browser ──────▶ Proxy ──────▶ Web Server
│
┌──────┴──────┐
│ Intercept │
│ Modify │
│ Replay │
│ Record │
└─────────────┘
Why use a proxy?
├── Inspect all HTTP/HTTPS traffic
├── Modify requests before they reach server
├── Modify responses before they reach browser
├── Automate testing (fuzzing, scanning)
└── Record traffic for analysis and reporting
2. Burp Suite — Setup and Configuration
Burp Suite Editions:
Community (Free):
├── Proxy, Repeater, Decoder, Comparer
├── Intruder (rate-limited)
└── No Scanner, no saving
Professional ($449/year):
├── Full Scanner (active + passive)
├── Intruder (no rate limit)
├── Collaborator (OOB testing)
├── Extensions (BApp Store)
└── Save/restore projects
Enterprise (server-based):
└── CI/CD integration, scheduled scans
Setup:
1. Download from portswigger.net
2. Configure proxy: 127.0.0.1:8080
3. Install CA certificate in browser
4. Configure browser to use proxy
5. Turn on Intercept → browse target
Essential Burp Extensions (BApp Store):
├── Active Scan++ : Enhanced scanner checks
├── Autorize : Authorization testing
├── Logger++ : Enhanced logging
├── JSON Beautifier: Format JSON in Proxy
├── Param Miner : Hidden parameter discovery
├── Turbo Intruder: Fast, scriptable Intruder
├── JWT Editor : JWT manipulation
├── Hackvertor : Encoding/decoding tags
└── Upload Scanner: File upload testing
3. Burp Proxy & Repeater
Proxy Tab Workflow:
1. Intercept ON → browse target application
2. Examine each request:
- Check parameters, cookies, headers
- Look for auth tokens, session IDs
3. Forward, Drop, or send to Repeater/Intruder
4. Review HTTP history for all captured traffic
Repeater — Manual Testing:
1. Send interesting request to Repeater (Ctrl+R)
2. Modify parameters one at a time
3. Send and analyze response
4. Common tests:
- Change user ID → IDOR
- Add admin=true → privilege escalation
- SQL payloads in parameters → injection
- XSS payloads in input fields
- Remove auth headers → access control
### Example: Testing IDOR in Repeater
# Original request:
GET /api/v1/users/123/orders HTTP/2
Host: api.example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...
Cookie: session=abc123
# Modified — change user ID:
GET /api/v1/users/456/orders HTTP/2
Host: api.example.com
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...
Cookie: session=abc123
# If response 200 with user 456's data → IDOR confirmed!
### Example: Testing parameter pollution
POST /api/v1/transfer HTTP/2
Host: api.example.com
Content-Type: application/json
Authorization: Bearer eyJhbGciOiJSUzI1NiIs...
{"from": "123", "to": "456", "amount": 100, "amount": -100}
# Some parsers take last value → negative transfer
4. Burp Intruder — Automated Attack
Intruder Attack Types:
Sniper: One payload position at a time
Battering Ram: Same payload in all positions
Pitchfork: Different payloads, synchronized
Cluster Bomb: All combinations of payloads
Example: Brute-force login
POST /login
username=§admin§&password=§P@ssw0rd§
Attack Type: Cluster Bomb
Position 1 (username): admin, root, administrator
Position 2 (password): wordlist (rockyou-top-1000.txt)
Total requests: 3 × 1000 = 3000
Analyzing Results:
- Sort by Status Code (200 vs 401)
- Sort by Response Length (different = interesting)
- Sort by Response Time (longer = potential timing attack)
- Grep for keywords ("success", "welcome", "invalid")
Turbo Intruder Script (Python/Jython):
# For high-speed attacks (bypassing rate limits)
def queueRequests(target, wordlists):
engine = RequestEngine(
endpoint=target.endpoint,
concurrentConnections=5,
requestsPerConnection=100,
pipeline=True
)
for word in open('/usr/share/wordlists/common.txt'):
engine.queue(target.req, word.rstrip())
def handleResponse(req, interesting):
if req.status == 200:
table.add(req)
# Race condition testing:
# if req.status != 429:
# table.add(req)
5. Burp Scanner (Pro)
Scanner Modes:
Passive Scan:
├── Analyzes existing traffic (no extra requests)
├── Finds: cookies without flags, info disclosure
├── Missing headers, sensitive data in URLs
└── Always running in background
Active Scan:
├── Sends additional requests to test vulnerabilities
├── Finds: SQLi, XSS, SSRF, command injection
├── Can be noisy (triggers WAF/IDS)
└── Right-click → "Scan" on specific requests
Scan Configuration:
├── Audit items: Select which checks to run
├── Crawl: Configure crawl depth and scope
├── Handling: Login macros, session handling rules
└── Reporting: Generate HTML/XML reports
6. OWASP ZAP — Free Alternative
# --- OWASP ZAP Installation ---
# Docker (recommended)
docker pull ghcr.io/zaproxy/zaproxy:stable
# --- ZAP CLI Commands ---
# Quick scan (spider + active scan)
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
zap-full-scan.py -t https://example.com \
-r zap_report.html
# API scan (OpenAPI/Swagger)
docker run --rm -v $(pwd):/zap/wrk ghcr.io/zaproxy/zaproxy:stable \
zap-api-scan.py -t https://example.com/openapi.json \
-f openapi \
-r api_report.html
# Baseline scan (passive only — safe for production)
docker run --rm ghcr.io/zaproxy/zaproxy:stable \
zap-baseline.py -t https://example.com \
-r baseline_report.html
# --- ZAP with authentication ---
docker run --rm -v $(pwd):/zap/wrk ghcr.io/zaproxy/zaproxy:stable \
zap-full-scan.py -t https://example.com \
-r auth_report.html \
-z "-config auth.loginurl=https://example.com/login \
-config auth.username=test \
-config auth.password=Test123!"
# --- ZAP Automation Framework ---
# zap-automation.yaml
env:
contexts:
- name: "Example App"
urls:
- "https://example.com"
includePaths:
- "https://example.com/.*"
excludePaths:
- "https://example.com/logout.*"
authentication:
method: "form"
parameters:
loginPageUrl: "https://example.com/login"
loginRequestUrl: "https://example.com/api/auth/login"
loginRequestBody: "username={%username%}&password={%password%}"
verification:
method: "response"
loggedInRegex: "\\Qdashboard\\E"
users:
- name: "test-user"
credentials:
username: "testuser"
password: "TestPassword123!"
jobs:
- type: spider
parameters:
maxDuration: 5
maxDepth: 5
maxChildren: 10
- type: spiderAjax
parameters:
maxDuration: 5
- type: passiveScan-wait
parameters:
maxDuration: 5
- type: activeScan
parameters:
maxRuleDurationInMins: 5
maxScanDurationInMins: 30
policy: "Default Policy"
- type: report
parameters:
template: "traditional-html"
reportDir: "/zap/wrk"
reportFile: "zap-scan-report"
risks:
- high
- medium
- low
7. ZAP in CI/CD Pipeline
# .github/workflows/security-scan.yml
name: DAST Security Scan
on:
push:
branches: [main, develop]
schedule:
- cron: '0 2 * * 1' # Weekly Monday 2AM
jobs:
zap-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Start application
run: |
docker-compose up -d
sleep 30 # Wait for app to be ready
- name: ZAP Baseline Scan
uses: zaproxy/[email protected]
with:
target: 'http://localhost:3000'
rules_file_name: 'zap-rules.tsv'
cmd_options: '-a'
- name: ZAP Full Scan
if: github.ref == 'refs/heads/main'
uses: zaproxy/[email protected]
with:
target: 'http://localhost:3000'
rules_file_name: 'zap-rules.tsv'
- name: Upload ZAP Report
uses: actions/upload-artifact@v4
if: always()
with:
name: zap-report
path: report_html.html
# zap-rules.tsv — Customize alert handling
# WARN = report but don't fail
# FAIL = fail the CI pipeline
# IGNORE = skip this check
10011 WARN (Cookie Without Secure Flag)
10015 FAIL (Incomplete or No Cache-control)
10020 FAIL (X-Frame-Options Header Missing)
10021 FAIL (X-Content-Type-Options Missing)
10038 FAIL (Content Security Policy Missing)
10098 WARN (Cross-Domain Misconfiguration)
40012 FAIL (Cross Site Scripting Reflected)
40014 FAIL (Cross Site Scripting Persistent)
40018 FAIL (SQL Injection)
90033 FAIL (Loosely Scoped Cookie)
8. Compare Burp Suite Pro vs OWASP ZAP
| Feature | Burp Suite Pro | OWASP ZAP |
|---|---|---|
| Price | $449/year | Free / Open Source_ |
| Scanner | Industry-leading_ | Good, improve_ |
| Extensions_ | BApp Store (rich)_ | Marketplace (growing) |
| Intruder | Full-speed | Fuzzer (basic) |
| Collaborator | Built-in OOB server_ | No equivalent_ |
| CI/CD | Enterprise edition | Native (GitHub Actions) |
| API | REST API (Enterprise) | Full REST API (free) |
| Learning | _PortSwigger Academy | Community docs_ |
| Best for_ | Professional pentesters_ | DevSecOps, automation |
9. Summary
- Burp Suite: Industry standard — Proxy, Repeater, Intruder, Scanner
- OWASP ZAP: Free alternative — excellent for CI/CD automation
- Proxy workflow: Intercept → Analyze → Modify → Replay → Report
- CI/CD integration: ZAP GitHub Actions for automated DAST
- Best practice: Use both — ZAP for automation, Burp for manual testing
The next article will delve into Exploitation Frameworks — Metasploit.