How to do it...

Let's use the Burp Suite Spider to perform the web application attack:

  1. To begin automatically spidering the web content from your previously defined scope, click on the Spider tab at the top of the screen. Underneath, there are two additional tabs that include Control and Options.
  2. The Options tab allows the user to define the configurations for how spidering is performed. This includes detailed settings, depth, throttling, form submissions, and so on. It is important to consider the configurations of an automatic spider, as it will be sending requests to all in-scope web content. This could potentially be disruptive or even damaging to some web content.
  1. Once configured, the Control tab can be selected to begin automatic spidering. By default, the Spider tab is paused. By clicking on the button that indicates such, the spider can be started. The Site map tab under the Target tab will be automatically updated as the spider progresses. Have a look at the following screenshot:
  1. Depending on the configurations defined, Burp Suite will likely request your interaction with any forms that it encounters while spidering. Enter parameters for any forms identified, or skip the forms by selecting the Ignore form button, as shown in the following screenshot:
  1. Alternatively, you can spider from any particular location by right-clicking on it in the Site map tab and then clicking on Spider this branch. This will recursively spider the object selected and any files or directories contained within. Have a look at the following screenshot:
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset