burpsuite automation

Automation and web application penetration testing just don’t go well together. With the web applications all being different in behavior, this is just the way it goes. There are automated tools, some better than others, but at the end of the day, automation and high quality web application testing just do not go hand in hand.

Burpsuite is a tool (and is also amazing) so that you can use to achieve some automation as well as have the granularity that is necessary to control the testing. While it’s pretty much a guarantee no two websites are alike, patterns remain similar. Having control and a grasp of what’s similar and not allows a greater quality penetration test.

While I’m not going to rewrite on how to use the attack/replay module on burpsuite as there are so many tutorials (basic to advanced) out there (like this short one), what I will recommend these lists of attacks you can load into burpsuite so that you can test against blind SQL injection vulnerabilities against input fields in a webapp.

 

One thought on “burpsuite automation

Leave a comment