cybersecurity:tools:burpsuite
Differences
This shows you the differences between two versions of the page.
| cybersecurity:tools:burpsuite [2026/09/20 14:22] – created warnaud | cybersecurity:tools:burpsuite [2026/09/20 14:27] (current) – warnaud | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| ===== Pre ===== | ===== Pre ===== | ||
| {{ : | {{ : | ||
| + | Most bug hunters open Burp Suite the moment they get a target. | ||
| + | I wait. | ||
| + | |||
| + | Here are the 5 things I do before touching Burp Suite: | ||
| + | |||
| + | - Google Dorking the target \\ site: | ||
| + | - Subdomain enumeration \\subfinder + httpx pipeline.\\I' | ||
| + | - JavaScript file hunting\\I run waybackurls + gf on every JS file.\\Devs leave API keys, internal routes, and hardcoded tokens here more than anywhere else. | ||
| + | - Reading the job listings\\The company' | ||
| + | - Checking old vulnerability disclosures\\Search HackerOne' | ||
| + | |||
| + | Burp Suite is a powerful tool. | ||
| + | But it's useless without knowing where to point it. | ||
| + | |||
| + | Recon is where 80% of my findings actually start. | ||
| + | |||
| + | Save this. You'll use it. | ||
| + | |||
| + | Which step surprised you the most? Drop it below 👇 | ||
| + | |||
| + | — @sheoraninfosec | ||
| + | Bug Bounty Hunter · HackerOne & Intigriti | ||
| + | Original post: https:// | ||
cybersecurity/tools/burpsuite.1789906943.txt.gz · Last modified: by warnaud
