3 ms·
Burp Suite has a pretty rich feature set. How does this compare? For example, is something scriptable like Burp Intruder included (or planned)?
by sdevlin 12y ago
Burp Suite has a pretty rich feature set. How does this compare? For example, is something scriptable like Burp Intruder included (or planned)?
- passfree 12y agoBurp Suite is one-size-fits-all type of solution. Indeed, it comes with a lot of other tools which are primarily used for penetration testing. On the other hand, Proxy.app is just a good proxy and already comes with many of useful features. It is faster, feels native and available at the fraction of the cost of Burp. It is more general purpose proxy tool than a general purpose security testing framework. The tool can be nicely complemented by some of the other tools from Websecurify.
- tptacek 12y agoBurp has a lot of features, but at it's core it's four things: * Proxy records, categorizes, and makes searchable and navigable all the requests you make through Burp, and includes an internal CA to generate on-the-fly SSL certificates. * Spider crawls websites and discovers new pages. * Repeater takes requests from any other part of the tool (or, if you're masochistic, requests you write from scratch), delivers them to the target application, and renders their results. Repeater includes Burp's UI for breaking requests into keys and values for quick editing, and a small battery of fixups to make sure that edited requests are (if you want them to be) valid HTTP requests. * Intruder takes a template request and a series of rules to transform that request, delivers the permutations rapidly to the target, and records and classifies the responses they generate. Of these four tools, only the "Spider" is really particular to penetration testing. The other three tools are incredibly valuable for day-to-day debugging and testing. Intruder, in particular, is criminally undersold to web developers. There are a bunch of other things in Burp (the Burp Scanner, for instance, is a second-tier web application security scanner that nobody I know relies on; I justify pulling it out of the core four features because it's also a recent arrival to Burp). Some of them are given whole tabs in the UI, but are really simple features --- the "Decoder", for instance, simply does character decoding. In any case, even penetration testers don't use them often.
- passfree 12y agoHi tptacek, Indeed security tools should be part of the developer's workflow but not necessarily the way they are presented in Burp. We are yet to see a horde of developers who can spend spare time fiddling with requests in order to find bugs in their own code. There are not only time constraints but also this type of thinking is not natural to everyone. Websecurify is working hard to find out better ways to enable developers do the minimum security testing without getting in their way.
- tptacek 12y agoI'm not saying developers should use security tools to do security testing (although that is also a good idea). I'm saying that in terms of the day-to-day workload of developers building web apps or APIs, a tool like Burp is as valuable or more valuable than a debugger is to a C programmer.