Burp Flashcards

(25 cards)

1
Q

What is the primary function of the Burp Suite Proxy tool?

A

To intercept and modify HTTP/S traffic between the browser and the server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

True or False: The Repeater tool in Burp Suite allows you to modify and resend individual HTTP requests.

A

True.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Fill in the blank: The __________ tool is used to automate the sending of multiple requests to a web application.

A

Intruder

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the purpose of the Decoder tool in Burp Suite?

A

To decode and encode data in various formats such as Base64, URL encoding, and HTML encoding.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which Burp Suite tool would you use to compare two responses to identify differences?

A

Comparer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the main use of the Sequencer tool?

A

To analyze the randomness of tokens and session IDs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Multiple Choice: Which tool allows you to quickly test for vulnerabilities by sending crafted payloads? A) Proxy B) Repeater C) Intruder D) Decoder

A

C) Intruder.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

True or False: The Proxy tool can only intercept HTTP traffic.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What type of analysis does the Comparer tool perform?

A

It performs a side-by-side comparison of two pieces of data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Fill in the blank: The __________ tool is essential for testing the security of web applications by analyzing session tokens.

A

Sequencer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What feature does the Repeater tool provide that is crucial for manual testing?

A

It allows testers to modify requests and observe server responses in real-time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

True or False: The Intruder tool requires manual input for every request it sends.

A

False.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What formats can the Decoder tool handle?

A

Base64, URL encoding, HTML encoding, and others.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which Burp Suite tool is best suited for session management testing?

A

Sequencer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Multiple Choice: The primary use of the Proxy tool is to: A) Decode data B) Intercept traffic C) Compare responses D) Automate requests

A

B) Intercept traffic.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is the main benefit of using the Comparer tool?

A

It helps identify differences in responses for security analysis.

17
Q

Fill in the blank: Burp Suite’s __________ tool allows users to perform payload injection attacks.

18
Q

True or False: The Decoder tool can only decode data, not encode it.

19
Q

What does the Sequencer tool analyze to determine security strength?

A

The randomness of session tokens or identifiers.

20
Q

Which tool would you use for testing an application’s input validation?

21
Q

What does the Proxy tool allow you to do with the intercepted requests?

A

Modify and resend them.

22
Q

Multiple Choice: Which tool would be least useful for analyzing the randomness of session tokens? A) Sequencer B) Repeater C) Decoder D) Comparer

23
Q

True or False: The Repeater tool can be used to perform brute-force attacks.

24
Q

What type of testing is the Intruder tool primarily designed for?

A

Automated vulnerability testing.

25
Fill in the blank: The __________ tool is primarily used to analyze differences in responses or data sets.
Comparer