WebApp Sec mailing list archives

Re: BurpSuite newbie


From: Steve Pinkham <steve.pinkham () gmail com>
Date: Fri, 06 Feb 2009 21:02:03 -0500

Andre Rodrigues wrote:
Hi Ken,

Thanks for instant reply.

I use version 1.2.

The tool is working fine.
But I don´t know what type of tests to make and neither how to do it. Can you tell me about any site or book with these 
tests?


Thanks,
André

+1 to the Web Application Hackers Handbook as the seminal work on the topic, but the OWASP Testing Guide is a good intro and a free download you can start working with today.

PDF version:
http://www.owasp.org/images/5/56/OWASP_Testing_Guide_v3.pdf
Main page:
http://www.owasp.org/index.php/Category:OWASP_Testing_Project

The best way to learn is by doing, and OWASP WebGoat is a good interactive learning environment. It's also quite easy to try out using the OWASP Live cd, which has both burp and webgoat ready to run, plus much more.

http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project

Steve
--
 | Steven E. Pinkham                      |
 | GPG public key ID CD31CAFB             |

-------------------------------------------------------------------------
Sponsored by: Watchfire Methodologies & Tools for Web Application Security Assessment With the rapid rise in the number and types of security threats, web application security assessments should be considered a crucial phase in the development of any web application. What methodology should be followed? What tools can accelerate the assessment process? Download this Whitepaper today!
https://www.watchfire.com/securearea/whitepapers.aspx?id=70170000000940F
-------------------------------------------------------------------------


Current thread: