Dheerajs2/Burp-Suite-Fundamentals

GitHub: Dheerajs2/Burp-Suite-Fundamentals

基于 DVWA 靶场的 Burp Suite 社区版基础教学项目,演示 Web 应用安全测试中 HTTP 请求拦截、修改与分析的完整流程。

Stars: 0 | Forks: 0

# Burp Suite 基础 ![平台](https://img.shields.io/badge/Platform-Kali_Linux-red) ![工具](https://img.shields.io/badge/Tool-Burp_Suite-orange) ![目标](https://img.shields.io/badge/Target-DVWA-green) ![状态](https://img.shields.io/badge/Status-Completed-brightgreen) # 概述 本项目演示了 Burp Suite 社区版在 Web 应用安全测试中的基础功能。使用托管在 Ubuntu Server 上的 DVWA (Damn Vulnerable Web Application),通过拦截、修改、分析和比较 HTTP 请求与响应,来了解常见的 Web 应用测试工作流程。 # 目标 - 配置 Burp Suite - 配置 Firefox 代理 - 拦截 HTTP 请求 - 分析 HTTP 流量 - 使用 Repeater 修改请求 - 使用 Intruder 测试参数 - 编码与解码数据 - 比较请求与响应 - 探索 Target 站点地图 # 实验环境 | 组件 | 详情 | |-----------|---------| | 宿主机操作系统 | Windows 11 | | Hypervisor | VMware Workstation 17 | | 攻击机 | Kali Linux | | 目标机 | Ubuntu Server | | Web 服务器 | Apache2 | | 数据库 | MariaDB | | 应用程序 | DVWA | | 工具 | Burp Suite 社区版 | # 使用的 Burp Suite 模块 - Proxy - Target - Repeater - Intruder - Decoder - Comparer # 展示的技能 - HTTP 请求分析 - HTTP 响应分析 - 代理配置 - 请求拦截 - 手动请求修改 - 参数测试 - Base64 编码与解码 - URL 编码 - Web 应用枚举 # 学习成果 本项目提供了使用 Burp Suite 社区版的实践经验,以了解 Web 应用程序的通信方式,以及如何在安全的实验室环境中检查、修改和分析 HTTP 请求。 # 免责声明 所有测试均仅针对在个人 VMware 实验室中托管的 DVWA 进行,仅供学习交流之用。 # 作者 **Dheeraj S** 有志成为 SOC Analyst | Cybersecurity Analyst
标签:Burp Suite, CISA项目, DVWA, HTTP流量分析, Web安全, 安全实验, 蓝队分析, 防御绕过