Jastes 2023. 2. 2. 16:37

Burp Suite Download

 

Download Burp Suite Community Edition - PortSwigger

Burp Suite Community Edition is PortSwigger's essential manual toolkit for learning about web security testing. Free download.

portswigger.net

์œ„ ๋งํฌ๋ฅผ ๋“ค์–ด๊ฐ€์„œ..

์œ„๋ฅผ ํด๋ฆญํ•˜๊ณ  ์„ค์น˜ ํ›„.. ๋“ค์–ด๊ฐ€์‹œ๊ณ 
๊ทธ๋ƒฅ ์ „๋ถ€ ๋™์˜ ๋ฐ ์„ค์ • ๋”ฑํžˆ ๊ฑด๋“œ๋ฆฌ์ง€ ๋ง๊ณ  ์‹คํ–‰ํ•˜์‹ ๋‹ค๋ฉด..

์งœ๋ž€! ์‹คํ–‰์ด ๋œ๋‹ต๋‹ˆ๋‹ค!(๊ทผ๋ฐ ์ €๋Š” Kali linux๋กœ ์‹คํ–‰ํ• ๊ฒ๋‹ˆ๋‹ค ใ…Ž)
์ฐธ๊ณ ๋กœ ์–ด๋‘ก๊ฒŒ ํ•˜๊ณ  ์‹ถ๋‹ค๋ฉด..

์˜†์— Settings์—์„œ UI๋‚˜ ํˆด ๋“ฑ์˜ ์œ„์น˜ ๋ฐ UX๋ฅผ ์ปค์Šคํ…€๋งˆ์ด์ง• ํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์•Œ์•„๋‘๋ฉด ์ข‹๊ฒ ์ฃ ?


Burp Suite Using Guide

 

How to use Burp Suite for penetration testing

The sections below describe the essentials of how to use Burp Suite within your web application testing workflow. For help with installing and launching ...

portswigger.net

Burp Suite์—๋Š” ๋งค์šฐ ๋‹ค์–‘ํ•œ ๊ธฐ๋Šฅ์ด ์žˆ๋Š”๋ฐ ์—ฌ๊ธฐ์„œ ์ฃผ๋กœ ์‚ฌ์šฉ๋˜๋Š” ๋ถ€๋ถ„์ด Proxy๋ผ๋Š” ๋ถ€๋ถ„์ž…๋‹ˆ๋‹ค.

๊ฐ€์žฅ ๋Œ€ํ‘œ์ ์ธ ๊ธฐ๋Šฅ์œผ๋กœ์จ, ์›น ํ”„๋ก ๊ธฐ๋Šฅ์„ ํ†ตํ•ด ์˜ค๊ณ ๊ฐ€๋Š” Request-Response๋ฅผ ์ฒ˜๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
๊ธฐ๋ณธ์ ์œผ๋ก  localhost(127.0.0.1)์— ์ง€์ •๋œ ํ”„๋ก์‹œ ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•˜๋ฉฐ,
ํ”„๋ก์‹œ ์‘๋‹ต์„ ๋ฐ›๊ธฐ ์œ„ํ•ด์„ ..Proxy Listeners ์„ค์ •์„ ์ถ”๊ฐ€ํ•ด์•ผํ•ฉ๋‹ˆ๋‹ค.

๋˜ํ•œ ์ €ํฌ๋Š” Community(free tire)๋กœ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ ์œ ์˜ํ•˜์„ธ์š”
pro ๋ฒ„์ „๊ณผ ๊ธฐ์—…์—์„œ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ์‹์€ ์•ฝ๊ฐ„์”ฉ ์ฐจ์ด๊ฐ€ ์žˆ์œผ๋ฉฐ, ๋Œ€ํ‘œ์ ์œผ๋ก  ์•„๋ก€ ์˜์ƒ์—์„œ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค.


Proxy Settings

Proxy๋ž€?
 

Proxy meaning

ํ”„๋ก์‹œ(Proxy)๋ž€? ์˜๋ฌธ ์˜๋ฏธ๋ก  "๋Œ€๋ฆฌ"๋ผ๋Š” ์˜๋ฏธ๋ฅผ ๊ฐ–์Œ ํ”„๋ก์‹œ ์„œ๋ฒ„๋กœ์จ Client๊ฐ€ ์ž์‹ ์„ ํ†ตํ•ด์„œ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ ์„œ๋น„์Šค๋ฅผ ๊ฐ„์ ‘์ ์œผ๋กœ ์ ‘์†ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ฃผ๋Š” ์ปดํ“จํ„ฐ ์‹œ์Šคํ…œ์ด๋‚˜ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์„

dystopia050119.tistory.com

์ž์‹ ์˜ IP๋ฅผ ํ™•์ธ ํ›„ Proxy Listeners์— ์ง€์ • ํ›„ ์ถ”๊ฐ€์ ์ธ ์„ค์ •์„ ํ•˜์…”๋„ ๋˜๊ณ .. ์•„๋‹ˆ๋ฉด

01

์œ„์™€ ๊ฐ™์ด ์„ค์ •ํ•˜์…”๋„ ๋˜๋ฉฐ, ์ฃผ์˜์‚ฌํ•ญ์œผ๋กœ๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ์›น ์„œ๋น„์Šค์˜ ์‹คํ–‰์€ ์•ˆ๋˜๋ฏ€๋กœ
burp suite ์‚ฌ์šฉ์‹œ์—๋งŒ proxy ์„ค์ •์„ ๊ถŒ์žฅ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ๋˜ ๋ธŒ๋ผ์šฐ์ € ๋ธŒ๋ก์‹œ๋„ ๋˜‘๊ฐ™์ด ์„ค์ •ํ•˜์‹œ๊ณ ์š”

๊ทผ๋ฐ ์ด์™€ ๊ฐ™์€ ๋ฐฉ๋ฒ•์ด ์˜ค๋ฅ˜๋‚˜ ๊ธฐํƒ€ ์„ค์ •์œผ๋กœ ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ๋„ ์กด์žฌํ•˜๋ฏ€๋กœ ์‰ฝ๊ฒŒ ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์œผ๋กœ๋Š”..

์ด๊ฑฐ ๋ˆ„๋ฅด์‹œ๋ฉด ๋ฐ”๋กœ ๋˜๊ธด ํ•ด์š” ใ…Ž์„ธ๋ถ€์ ์œผ๋กœ ๋งŽ์€ ๋‚ด์šฉ๊ณผ ๋‹ค๋ฃฐ ์ˆ˜ ์žˆ๋Š” ์„ค๋ช…์„ ํ•ด์•ผํ•˜๋‚˜..
๋„ˆ๋ฌด ๊ท€์ฐฎ์•„์„œ ํ•ด๋‹น ํ•™์Šต ๋งํฌ๋ฅผ ์˜ฌ๋ฆฌ๊ณ  ๋งˆ๋ฌด๋ฆฌ!

๊ณต์‹ ์‚ฌ์ดํŠธ์— ์ •๋ฆฌ๊ฐ€ ์ž˜๋˜์–ด ์žˆ์–ด์„œ ์˜์–ด๋งŒ ์ข€ ๋˜์‹œ๋ฉด ๊ฑฐ๊ธฐ๋ฅผ ๊ฐ•์ถ”ํ•ฉ๋‹ˆ๋‹ค!

 

How to use Burp Suite for penetration testing

The sections below describe the essentials of how to use Burp Suite within your web application testing workflow. For help with installing and launching ...

portswigger.net

 

[๋ฌด๋ฃŒ] ์›น ์„œ๋น„์Šค ํ•ดํ‚น์„ ์œ„ํ•œ ๋ฒ„ํ”„์Šค์œ„ํŠธ ์™„๋ฒฝ ํ™œ์šฉ ๊ฐ€์ด๋“œ - ์ธํ”„๋Ÿฐ | ๊ฐ•์˜

์›น ์ทจ์•ฝ์  ๋ถ„์„ (ํ•ดํ‚น) ์„ ํ•  ๋•Œ ์ œ์ผ ๋งŽ์ด ์‚ฌ์šฉํ•˜๋Š” ๋„๊ตฌ๋Š” ์›น ํ”„๋ก์‹œ(Web Proxy) ์„œ๋ฒ„์ด๋‹ค. ๊ทธ ์ค‘์—์„œ ๋ฒ„ํ”„์Šค์œ„ํŠธ(BurpSuite)๋ฅผ ๋งŽ์ด ํ™œ์šฉํ•˜๊ฒŒ ๋œ๋‹ค. ๋ฒ„ํ”„์Šค์œ„ํŠธ๋ฅผ ํ™œ์šฉ๋ฒ•์„ ์ •๊ธฐ์ ์œผ๋กœ ์—…๋ฐ์ดํŠธ ํ•˜

www.inflearn.com

2๋ฒˆ์งธ๊บผ๋Š” ์ €๋„ ์•ˆ ๋ดค๋Š”๋ฐ.. ์†”์งํžˆ ๋ณด์•ˆํ”„๋กœ์ ํŠธ๊ฐ€ ์ €๋Š” ์ข€ ๋‹ต๋‹ตํ•ด์„œ ๊ทธ๋ž˜๋„ ์ข‹์€ ๋‚ด์šฉ์ด์˜ˆ์š”
๋˜ํ•œ ์›น ๊ณต๋ถ€ํ•˜์‹ค ๋•Œ PortSwigger Academy ๋‚ด์šฉ์ด ์ง„์งœ ๋„ˆ๋ฌด ์ข‹์€๋ฐ.. ๋งŽ์ด ์–ด๋ ต๊ธฐ๋„ ํ•ด์„œ์š”

Dreamhack๊ฐ™์€ ๊ณณ์—์„œ ๊ธฐ์ดˆ๋Š” ๋งŽ์ด ์Œ“์œผ์‹œ๊ณ  ๋“ค์œผ์‹œ๋Š” ๊ฑธ ์ถ”์ฒœํ•˜๋‚˜ ์ €๋Š” ์˜์–ด๋ฅผ ๋ชปํ•ด์„œ ๊ทธ๋Ÿฐ๊ฑฐ๊ณ 
๋˜์‹ ๋‹ค๋ฉด Academy๋ฅผ ์ˆ˜๊ฐ•ํ•˜์‹œ๋Š” ๊ฑธ ์ถ”์ฒœ๋“œ๋ฆฝ๋‹ˆ๋‹ค.(์ €๋„ ์ฐ๋จนํ•ด์„œ.. ๋‚˜์ค‘์— ํ•ด์•ผ์ฃ ..)


์ฐธ๊ณ  ์ž๋ฃŒ

์ฐธ๊ณ  ์ด๋ฏธ์ง€