Burp Suite Playbook
Burp Suite เป็นเครื่องมือทดสอบความปลอดภัยเว็บที่ใช้กันแพร่หลายที่สุด คู่มือนี้ครอบคลุมการตั้งค่า proxy, การใช้ทุก tab หลัก (Proxy, Repeater, Intruder, Decoder, Comparer), attack types ของ Intruder, และ workflow การทดสอบเว็บแบบใช้งานจริง
1. ตั้งค่า proxy + intercept
Burp ทำงานเป็น intercepting proxy — นั่งกลางระหว่าง browser กับ server ทำให้ดู/แก้ทุก request ได้ ต้องตั้ง browser ให้ส่งผ่าน Burp และติดตั้ง CA certificate ของ Burp เพื่อ intercept HTTPS
- 1Burp Proxy listener default ที่ 127.0.0.1:8080
- 2ตั้ง browser proxy → 127.0.0.1:8080 (แนะนำใช้ FoxyProxy หรือ Burp's browser)
- 3ติดตั้ง CA cert: เข้า http://burp → CA Certificate → import เข้า browser (สำหรับ HTTPS)
- 4Proxy → Intercept ON/OFF: ON = หยุดทุก request ให้แก้, OFF = ผ่านแต่บันทึกใน HTTP history
- 5ดูทุก request ที่ผ่านใน Proxy → HTTP history
2. Tab หลักและหน้าที่
| Tab | ใช้ทำอะไร |
|---|---|
| Proxy | intercept/ดู/แก้ request ระหว่าง browser↔server |
| Repeater | ส่ง request ซ้ำ + แก้ทีละครั้ง (ทดสอบ manual) |
| Intruder | automate ส่งหลาย request (brute/fuzz) |
| Decoder | encode/decode (base64, URL, hex, hash) |
| Comparer | เทียบ response สองอัน (หาความต่าง) |
| Sequencer | วิเคราะห์ความสุ่มของ token/session |
| Target → Site map | โครงสร้างเว็บที่เจอทั้งหมด |
3. Repeater — ทดสอบ manual
Repeater คือ tab ที่ใช้บ่อยสุดในการทดสอบ manual — ส่ง request เดิมซ้ำๆ พร้อมแก้ทีละนิดเพื่อดูว่า server ตอบต่างกันยังไง เหมาะกับทดสอบ injection, IDOR, auth bypass
- 1จาก Proxy history → คลิกขวา request → Send to Repeater (Ctrl+R)
- 2แก้ request (parameter, header, method, body) ตามต้องการ
- 3Send → ดู response ทางขวา
- 4แก้แล้วส่งซ้ำเรื่อยๆ เทียบผล (เช่นเปลี่ยน id=1 → id=2 ทดสอบ IDOR)
- 5ใช้ทดสอบ SQLi/SSTI/command injection ทีละ payload
4. Intruder — automate attack
Intruder ส่ง request หลายครั้งโดยแทนค่าใน 'payload position' อัตโนมัติ — ใช้ brute-force, fuzzing, enumeration มี 4 attack type:
| attack type | การทำงาน | ใช้เมื่อ |
|---|---|---|
| Sniper | 1 payload set, ทีละตำแหน่ง | fuzz ทีละ field |
| Battering ram | 1 payload set, ทุกตำแหน่งพร้อมกัน | ค่าเดียวกันหลายที่ |
| Pitchfork | หลาย set, จับคู่ขนาน | username+password คู่กัน |
| Cluster bomb | หลาย set, ทุก combination | ลองทุกคู่ user×pass |
- 1Send to Intruder (Ctrl+I) จาก request
- 2Positions: เลือกตำแหน่งที่จะแทนค่า (กด Add §)
- 3เลือก attack type (Sniper/Cluster bomb/...)
- 4Payloads: ใส่ wordlist หรือ payload set
- 5Start attack → เรียงผลตาม status/length หา response ที่ต่าง (เจอช่องโหว่/credential)
5. Workflow ทดสอบเว็บ
- 1เปิด embedded browser → เดินเว็บให้ครบ (build site map ใน Target)
- 2ดู HTTP history หา request ที่น่าสนใจ (login, API, parameter)
- 3Send to Repeater ทดสอบ manual (injection/IDOR/auth)
- 4Send to Intruder ถ้าต้อง automate (fuzz/brute)
- 5Decoder ถอด token/encoded values; Comparer เทียบ response
- 6ใช้คู่ ffuf สำหรับ content discovery (proxy ffuf ผ่าน Burp -x)
6. Quick Reference
- setup: embedded browser (Proxy→Open Browser) ตั้งให้อัตโนมัติ
- Ctrl+R → Repeater (ทดสอบ manual, ส่งซ้ำแก้ทีละนิด)
- Ctrl+I → Intruder (automate: Sniper/Cluster bomb)
- Decoder: base64/URL/hex; Comparer: เทียบ response
- Intruder cluster bomb = ทุก combination user×pass
- brute เยอะ → ffuf/hydra เร็วกว่า CE Intruder
🧭 จับมือทำทีละขั้น (มีแค่ Kali) + ถ้าติดไปไหนต่อ
สมมติเจอเว็บเป้าหมายในโจทย์ที่ต้องทดสอบ manual (ต่างจาก directory fuzzing อัตโนมัติ) มีแค่ Kali ทำตามนี้ทีละขั้นเพื่อเริ่มดักจับและทดสอบ
- 1เช็คว่ามี Burp Suite ไหม: เปิดเมนู Kali หรือ `burpsuite &` (Kali มี Community Edition มาให้แล้ว)
- 2เปิด Burp → เลือก Temporary project → Use Burp defaults
- 3ไปที่ Proxy → Intercept → กด 'Open Browser' ใช้ browser ที่ฝังมาให้ (ตั้ง proxy/cert อัตโนมัติ ไม่ต้องเซ็ตเอง)
- 4เดินเว็บเป้าหมายให้ทั่ว (login, form, ทุกหน้า) ผ่าน browser นั้น — Burp บันทึกทุก request ไว้ที่ Proxy → HTTP history
- 5ถ้า HTTPS ไม่ขึ้น/หน้าเตือน cert → ตรวจว่าใช้ embedded browser จริงไหม ถ้าใช้ browser ปกติต้อง import CA cert เอง (http://burp → CA Certificate)
- 6ดู HTTP history หา request ที่น่าสนใจ (login, API endpoint, parameter แปลกๆ)
- 7คลิกขวา request → Send to Repeater (Ctrl+R) → แก้ parameter ทีละอัน → Send → เทียบ response
- 8สงสัย SQLi/IDOR/auth bypass → ลอง payload ใน Repeater ก่อน ถ้ายืนยันช่องโหว่ได้ → ไปหัวข้อเฉพาะเพื่อ exploit ต่อให้ลึก
- 9ต้อง brute/fuzz พารามิเตอร์จำนวนมาก → Send to Intruder (Ctrl+I) เลือก payload position + attack type
- 10Community Edition ช้า (throttle) ถ้างานใหญ่ → สลับไปใช้ ffuf/hydra แทน
| ขั้นตอน/งาน | เครื่องมือใน Kali | ติดตั้งเพิ่ม (ถ้าไม่มี) | เครื่องมือออนไลน์ |
|---|---|---|---|
| ดักจับ/แก้ request | burpsuite (embedded browser) | - | - |
| ทดสอบ manual | Repeater (Ctrl+R) | - | - |
| automate fuzz/brute | Intruder (Ctrl+I) | - | - |
| encode/decode ค่า | Decoder | - | cyberchef |
| เทียบ response | Comparer | - | - |
| หา endpoint เพิ่ม | - | ffuf, gobuster | - |
| brute จำนวนมาก (CE ช้า) | - | hydra | - |
| ทดสอบ JWT/token | - | - | jwt.io |
หัวข้อที่เชื่อมโยง
โน้ตของฉัน
ยังไม่มีโน้ตสำหรับหัวข้อนี้