Burp Suite Web Vulnerability Scanner

Some Windows servers perform specialized functions, and need to be assessed accordingly. For example, you should scan your web servers for general security vulnerabilities, but also scan them for vulnerabilities that are specific to web applications. The Burp Suite Web Vulnerability Scanner does just that. Burp Suite focuses on vulnerabilities found in web applications and makes it easy to scan for those weaknesses. Depending on your needs, you can get Burp Suite as Enterprise, Professional, or Community licenses. Each license provides different levels of service. The Community edition is free, but lacks the powerful Web Vulnerability Scanner. To get the scanner, you’ll need at least the Professional license. Figure 7-17 shows the defined web server target for a vulnerability scan. Figure 7-18 shows the results of a web vulnerability scan. Figure 7-19 shows an Executive Report that Burp Suite created based on the previous scan.

FIGURE 7-17 Defining the targets for a Burp Suite web vulnerability scan.

A screenshot of the burp suite professional page is shown. The proxy tab is selected at the top. It consists of a checkbox to use advanced scope control. The options add, edit, remove, paste URL, load, enabled, and prefix, are displayed separately to include in scope and exclude the scope.

Defining the targets for a Burp Suite web venerability scan.

Used with permission from PortSwigger Ltd.

FIGURE 7-18 Burp Suite web vulnerability scan results.

A screenshot of the burp suite professional application is shown. The target tab at the top is selected. Several panels display the results of the burp suite web vulnerability scan.

Burp Suite web vulnerability scan results.

Used with permission from PortSwigger Ltd.

FIGURE 7-19 Burp Suite web vulnerability scan results report.

A screenshot of the burp suite professional application shows an executive report on the burp suite web vulnerability scan results. A summary of the report is shown using a table and a graph. Also, the contents of the report are displayed.

Burp Suite web vulnerability scan results.

Used with permission from PortSwigger Ltd.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.