Skip to content

Burp Suite

Intercepting web proxy and testing workbench

VerifiedPentesting· Web Application TestingIntermediateProprietary (Community Edition is free to use)ProprietaryEntry revised 7 Jan 2026
  • Windows
  • macOS
  • Linux
  • Kali
This entry is thinner than the rest of the directory — missing sections are shown as such rather than filled with filler.Improve this pageContribute

Overview

4 commands documented

Burp Suite sits between a browser and an application as a TLS-terminating proxy, so requests can be inspected, modified and repeated. It is the standard interactive tool for web application testing: Repeater for one request at a time, Comparer for two responses, Sequencer for token entropy, Logger/BPG for the trail.

Community Edition provides the manual workflow. Professional adds the scanner, Collaborator and project files, and is licensed software — check current terms and pricing on the vendor site rather than assuming what a blog post said.

Supported platforms

4

Documented install or usage guidance

Learning curve

intermediate

Difficulty of becoming productive, not of the underlying theory

Tags

proxy, http, web, repeater, interception

Dataset entry

burp-suite.ts

Reviewed 2026-01-07

Installation

Grouped by platform. Elevation requirements are marked per method.

Official installer

RecommendedinstallerOfficial

Download the Windows installer for Community or Professional from the vendor's download page; the installer bundles a JRE.

Open official source

Package availability follows your distribution and enabled repositories. Entry revised 7 Jan 2026 — confirm the current release on the project's own download page.

Commands

4 entries

Every command carries its purpose, an example where useful, and the limitations that change how you should read the output.

01Point a browser at the proxy

bash

Burp listens on 127.0.0.1:8080 by default; browser-level proxying (or the Burp extension) avoids changing system-wide settings.

google-chrome --proxy-server='http://127.0.0.1:8080' --user-data-dir=/tmp/burp-profile

Notes

  • A dedicated profile keeps the proxy experiment away from your real browser state.

02Route a CLI request through Burp

bash

Useful for feeding scripted traffic into the same workspace you are testing from.

curl -x http://127.0.0.1:8080 -k -s -o /dev/null -w '%{http_code}\n' https://app.internal/login

03Install the CA certificate for TLS interception

bash

Export from Proxy → Options → CA certificate, then trust it only in the lab browser or VM you test with.

sudo security add-trusted-cert -d -r trustRoot -k /Library/Keychains/System.keychain burp-der.cer
  • A trusted interception CA lets the proxy decrypt TLS for that whole trust store. Install it in a lab VM or a browser profile — never on a machine you use for real accounts.

Notes

  • On Windows import into 'Trusted Root Certification Authorities' for the current user; on Linux place it in /usr/local/share/ca-certificates and run update-ca-certificates.

04Keep a portable project file

bash

Professional Edition writes a .burp project file so configuration, site map and issues travel with the engagement.

java -jar burpsuite_pro.jar --project-file=engagement-01.burp

Notes

  • Store project files encrypted: they contain session material, findings and internal hostnames.

What it is used for

  • Manual web application testing

    Inspect and repeat requests against in-scope endpoints.

  • API contract review

    Compare documented and observed behaviour of a JSON API.

  • Teaching HTTP

    See headers, cookies and status codes as they are actually sent.

Common errors

Symptoms you will actually hit, with the cause and the legitimate fix.

Browser errors with 'PR_SendReset / SSL_ERROR_BAD_CERT'Cause 1/3

Possible causes

  • The Burp CA is not trusted by the browser profile in use.

Usual fix

Install the exported CA into that profile's store (or Firefox's own certificate manager, which ignores the OS store unless enabled).

Intercept is on, and the browser just hangsCause 2/3

Possible causes

  • Requests are waiting in Proxy → Intercept.

Usual fix

Turn interception off, or use 'Intercept is off' by default and forward individual items to Repeater.

Mobile app or non-browser client ignores the proxyCause 3/3

Possible causes

  • Certificate pinning, or the client does not honour system proxy settings.

Usual fix

Pinning is a protection working as designed. Test the documented API instead, or ask the client about a debug build — do not try to defeat pinning outside scope.

Tips

  • Scope matters more than features: define target scope first so everything you log is intentionally in scope.
  • Disable 'hidden' content types you never want and keep the site map readable.
  • Every finding gets a Repeater tab that reproduces it — that tab is the report evidence.

Alternatives & comparisons

Not documented yet: zap. Request an entry and it will link up automatically.Request a tool

Side-by-side

References

Where to verify anything on this page. External links open in a new tab.

Found something wrong?Suggest an editMore in Pentesting

Looking for alternatives?

ffuf cover adjacent parts of the same job.

Compare side by side