2019-02-03T08:25:00Z

What is your primary use case for PortSwigger Burp?


How do you or your organization use this solution?

Please share with us so that your peers can learn from your experiences.

Thank you!

Guest
1010 Answers

author avatar
Top 10LeaderboardReal User

This is a solution for which I provide services to our customers and I also use it personally. As part of our organization, we build internal applications. Before they are put into production, we run a suite of security tests to ensure that our applications are not vulnerable to any known issues. We use PortSwigger Burp for testing, as well as OSASP Zap. We do similar tests in multiple tools to make sure that we cover the entire set of use cases. I have this solution deployed as one user on a single machine, which is used by a designated security tester.

2020-01-29T11:22:31Z
author avatar
Top 10LeaderboardReal User

Currently, we're trying to import the solution to implement it to other applications for our website. So far, it's been fantastic.

2020-01-19T06:38:00Z
author avatar
Top 5LeaderboardReal User

We use the solution for scanning our in-house external facing website.

2019-08-22T05:49:00Z
author avatar
Top 10LeaderboardReal User

The primary use case is security for the development lifecycle. We use the application for security testing.

2019-08-19T05:47:00Z
author avatar
Top 5LeaderboardReal User

Clients come to me for an assessment of their web applications to see the risks that they are facing with their applications. They want to ensure that their application is free of being manipulated and also secure, so they reach out to us to do vulnerability assessment and application penetration testing. We make use of PortSwigger's BurpSuite tool carry this out. We look at it more from an application standpoint, what common vulnerabilities there are like the top 10 OWASP vulnerabilities like Injection(OS/SQL/CMD), broken authentication, session management, cross site request forgery, unvalidated redirects/forwards, etc. Those are the primary uses we make use for this tool.

2019-07-08T07:42:00Z
author avatar
Top 20LeaderboardReal User

We use this solution for the security assessment of web applications before their release to the internet. The security assessment team uses this product to identify vulnerabilities and vulnerable code that developers may introduce. We host all of the beta applications in our internal web servers and then the security team starts assessments when the development freezes.

2019-07-07T00:05:00Z
author avatar
Top 5LeaderboardReal User

Our primary use for this solution is to perform vulnerability scanning before we deploy software in production.

2019-06-06T08:18:00Z
author avatar
Top 5LeaderboardReal User

I use this primarily for intercepting mobile HTTP and HTTPS requests with SSL pinning bypass. It's a better tool for manual tasks.

2019-05-29T23:42:00Z
author avatar
Real User

Our primary use case for this solution is to perform application security testing.

2019-05-16T07:47:00Z
author avatar
Consultant

My primary use case for this solution is designed around my own personal use. Burp Suite is a graphical tool for testing Web application security. The tool is written in Java.

2019-02-03T08:25:00Z
Learn what your peers think about PortSwigger Burp. Get advice and tips from experienced pros sharing their opinions. Updated: April 2020.
441,726 professionals have used our research since 2012.