Jason Gillam wanted to show you more about Portswigger’s Burp Suite, which is a very popular and flexible intercepting proxy tool among web application penetration testers. During this training session I will provide an overview of Burp Suite and how it can be extended to perform functions that are not directly available in the tool. The session will continue with a detailed explanation and demonstration of my Burp CO2 extension suite, using targets in the Samurai Web Testing Framework (Samurai WTF) distribution. Attendees may choose to follow along in their own Samurai WTF VM or just sit back and watch the show. Most CO2 modules will run in both the Free and Professional editions of Burp Suite.
Follow us on Socials:
Twitter: / secureideas
Facebook: / secureideasllc
LinkedIn: / secure-ideas
Timestamps:
0:00:00 - Start
0:00:14 - Opening of Web Penetration Testing with Burp & CO2
0:01:00 - Introduction of Jason Gillam
0:02:28 - Webcast Overview
0:04:13 - Web Penetration Testing
0:07:23 - Web Penetration Testing - Essential Skills
0:11:44 - Interception Proxy
0:13:36 - What is Burp? (Overview)
0:28:58 - What is CO2?
0:29:58 - What is Burp CO2 Really?
0:32:58 - Burp Extensions
0:34:51 - What can the Extender API Do and find the API
0:36:22 - How to write an Extension…
0:39:04 - Back to CO2 - CO2 Modules
0:51:49 - Demo time! - CO2 Tools
1:17:15 - Closing - Questions, Comments, Suggestions