Skip to content

Recon with Burp

Burp Suite's reconnaissance tools are essential for mapping web applications and uncovering hidden endpoints during penetration testing. By systematically analyzing HTTP traffic, leveraging automated tools, and manually testing endpoints, red teams can build a comprehensive understanding of the target's attack surface. This section covers advanced techniques for reconnaissance using Burp Suite's core tools.


Mapping the Application with the Scanner

Burp Scanner can automate the discovery of endpoints and vulnerabilities by crawling the application's structure. While primarily designed for vulnerability detection, its crawling capabilities help map the attack surface.

Steps:
1. Set the target URL in the Scanner's Target tab.
2. Configure the Scope to include relevant subdomains and endpoints.
3. Run the scan; Burp will intercept and analyze traffic, identifying endpoints, forms, and potential vulnerabilities.

Example:

# Set the target URL in Burp Scanner  
Target: https://example.com  
Scope: *.example.com  

Note: The Scanner may miss endpoints requiring authentication or dynamic parameters. Combine it with manual testing for completeness.


Identifying Hidden Endpoints with Intruder

Burp Intruder is ideal for fuzzing endpoints, headers, and parameters to uncover hidden or misconfigured paths.

Steps:
1. Intercept a request in the Proxy tab.
2. Send it to Repeater to analyze the response.
3. Use Intruder to replace a parameter (e.g., /login) with a payload list containing potential endpoints (e.g., /admin, /backup, /config).

Example:

GET / HTTP/1.1  
Host: example.com  

Payloads (Intruder):

/admin
/backup
/config
/secret

Attack Type:
- ** Sniper:** Test one payload at a time.
- Cluster Bomb: Test all payloads simultaneously.

Tip: Use common directory structures (e.g., /var, /tmp, /logs) or leaked paths from source code for payloads.


Manual Testing with Repeater

The Repeater tool allows precise modification of requests to test endpoints and observe responses.

Steps:
1. Intercept a request in the Proxy tab.
2. Send it to Repeater.
3. Modify parameters, headers, or URLs to simulate different scenarios (e.g., adding ?debug=1 to a query string).

Example:

GET /login?username=admin HTTP/1.1  
Host: example.com  
Cookie: session=abc123  

Observation:
- A 200 OK response with unexpected content (e.g., admin panel HTML) indicates a hidden endpoint.
- A 403 Forbidden response may suggest misconfigured access controls.


Leveraging the Proxy for Traffic Analysis

The Proxy tab is the primary tool for intercepting and analyzing all HTTP traffic.

Steps:
1. Enable interception in the Proxy tab.
2. Browse the target application to capture requests.
3. Analyze the Site Map (under the Scanner tab) to identify all discovered endpoints.

Example:

# Enable interception in Proxy  
Intercept: ON  

Key Insight:
- Use the Scope settings to filter traffic to relevant subdomains.
- Look for unusual endpoints (e.g., /api/v1/ or /swagger-ui/) that may indicate internal services.


Key takeaways

  • Use Burp Scanner to automate endpoint discovery and vulnerability detection.
  • Intruder is critical for fuzzing endpoints and uncovering hidden paths.
  • Repeater enables precise manual testing of suspicious endpoints.
  • The Proxy tab is indispensable for intercepting and analyzing all traffic during reconnaissance.
  • Always refine Scope settings to focus on relevant subdomains and paths.