offsecnotes

Burp Suite

by frankheat

Burp Scanner

Active scan

Right-click on a request and select “Do active scan”, Burp Scanner will use its default configuration to audit only this request.


Scan selected insertion point

Highlight the insertion point, right-click, and select “Scan selected insertion point” to focus on the input of interest and avoid unnecessary content.


Scan manual insertion point extension

Highlight a character sequence, usually a parameter value, and select Extensions > “Scan manual insertion point”.


Broken Access Control


PwnFox

PwnFox provide useful tools for your security audit


Out of band vulnerabilities

Many companies filtering and block outbound traffic to the default collaborator domain.


Logger ++ filters: Top 25 Parameters


Custom actions