Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Test web application security with Burp Suite. Use when a user asks to intercept HTTP traffic, test for web vulnerabilities, fuzz API endpoints, analyze authentication flows, or perform manual web application pentesting.
.claude/skills/terminalskills-burp-suite/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 67% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 73% | 0% |
| case-05 | ✓→✓ | = Same ✓ | 64% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 74% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 43% | 0% |
Burp Suite is the standard web application security testing platform. Its intercepting proxy captures and modifies HTTP/HTTPS traffic between browser and server. Includes: Scanner (automated vulnerability detection), Intruder (parameter fuzzing), Repeater (manual request modification), Sequencer (token randomness analysis), and Decoder (encoding/decoding). Community Edition is free; Professional adds the scanner and advanced features.
text1. Start Burp Suite → Proxy tab → Intercept is On 2. Configure browser proxy: 127.0.0.1:8080 3. Install Burp CA certificate for HTTPS interception: - Browse to http://burpsuite - Download CA certificate - Import into browser trust store 4. Browse the target application normally → Burp captures every request in HTTP History → Site map builds automatically from crawled pages
text# Proxy → HTTP History shows all captured requests: # Method URL Status Length # GET /api/v1/users/me 200 1,247 # GET /api/v1/projects 200 8,432 # POST /api/v1/projects 201 523 # GET /api/v1/projects/123/tasks 200 15,891 # PUT /api/v1/tasks/456 200 312 # DELETE /api/v1/tasks/789 403 89 # Right-click any request → Send to Repeater / Intruder / Scanner
text# Send a request to Repeater to modify and resend manually # Test IDOR: Change user ID in the request GET /api/v1/users/123/profile HTTP/1.1 → Change to: GET /api/v1/users/124/profile HTTP/1.1 → If 200 OK with different user's data → IDOR vulnerability # Test privilege escalation: Use regular user token on admin endpoint GET /api/v1/admin/users HTTP/1.1 Authorization: Bearer <regular-user-token> → If 200 OK → Broken access control # Test input validation: Inject payloads POST /api/v1/search HTTP/1.1 Content-Type: application/json {"query": "' OR 1=1--", "limit": 10} → If different response → possible SQL injection {"query": "<script>alert(1)</script>"} → If reflected in response → possible XSS
text# Send request to Intruder → mark injection points with § # IDOR enumeration: Fuzz user IDs GET /api/v1/users/§1§/transactions HTTP/1.1 → Payload: Numbers 1-1000 → Filter: responses with status 200 and different lengths → Every 200 = accessible user's transactions # Directory brute force GET /§admin§/ HTTP/1.1 → Payload: wordlist (common-dirs.txt) → Filter: status != 404 # Credential stuffing (authorized testing only) POST /api/v1/auth/login HTTP/1.1 {"email": "§user@example.com§", "password": "§password123§"} → Payload type: Pitchfork (parallel lists) → Payload 1: email list, Payload 2: password list → Filter: status 200 or different response length # Parameter fuzzing for injection POST /api/v1/products HTTP/1.1 {"name": "§test§", "category": "electronics"} → Payload: SQL/XSS/SSTI fuzzing wordlist → Monitor: response time (time-blind), errors (error-based), content changes
text# Active scan crawls and tests automatically # Target → Right-click → Scan # Scanner checks for: # - SQL injection (all techniques) # - Cross-site scripting (reflected, stored, DOM) # - Server-side request forgery (SSRF) # - Server-side template injection (SSTI) # - XML external entity injection (XXE) # - Path traversal # - OS command injection # - Authentication flaws # - Session management issues # - Information disclosure # Configure scan scope to stay within authorized targets: # Target → Scope → Include: *.target.example.com
text# BApp Store extensions (essential for pentesting): # Autorize — automatic authorization testing # Tests every request with a different user's session # Finds IDOR and privilege escalation automatically # Logger++ — advanced request logging with filters # Filter by regex, response codes, content types # Param Miner — discovers hidden parameters # Finds unlinked parameters that accept input # Turbo Intruder — high-speed fuzzing (Python scripted) # 10-100x faster than built-in Intruder # JWT Editor — decode, modify, and forge JWT tokens # Test: algorithm confusion, expired tokens, signature bypass # Hackvertor — encoding/decoding in-line within requests # Nest encodings: <@base64><@url>payload<@/url><@/base64>
text# Export findings: # Target → Issues → Right-click → Report selected issues # Format: HTML or XML # Includes: severity, confidence, evidence, remediation # Export requests for sqlmap or other tools: # Right-click request → Copy to file → Save as .txt # sqlmap -r saved-request.txt --batch # Export sitemap for documentation: # Target → Site map → Right-click → Save selected items
-r request.txt) for targeted injection testing.| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-05 | pass→pass | 15,138 | 16,003 | +6% | 1 | 1 | 0% | 2,595 | 4,255 | +64% | 0 | 0 | — |
case-06 | pass→pass | 12,631 | 14,176 | +12% | 1 | 1 | 0% | 2,365 | 4,107 | +74% | 0 | 0 | — |
case-01 | fail→pass | 10,611 | 8,479 | -20% | 1 | 1 | 0% | 1,903 | 3,169 | +67% | 0 | 0 | — |
case-02 | pass→pass | 15,121 | 15,282 | +1% | 1 | 1 | 0% | 2,902 | 4,155 | +43% | 0 | 0 | — |
case-03 | fail→pass | 16,198 | 17,178 | +6% | 1 | 1 | 0% | 2,792 | 4,827 | +73% | 0 | 0 | — |
case-04 | pass→pass | 12,224 | 9,142 | -25% | 1 | 1 | 0% | 2,362 | 3,093 | +31% | 0 | 0 | — |
case-07 | pass→pass | 14,942 | 12,761 | -15% | 1 | 1 | 0% | 1,288 | 2,462 | +91% | 0 | 0 | — |
case-08 | pass→pass | 6,948 | 5,961 | -14% | 1 | 1 | 0% | 1,038 | 2,609 | +151% | 0 | 0 | — |
case-09 | pass→pass | 5,917 | 3,192 | -46% | 1 | 1 | 0% | 891 | 2,036 | +129% | 0 | 0 | — |
case-10 | pass→pass | 5,688 | 4,729 | -17% | 1 | 1 | 0% | 994 | 2,328 | +134% | 0 | 0 | — |
case-11 | pass→pass | 7,719 | 3,727 | -52% | 1 | 1 | 0% | 1,461 | 2,219 | +52% | 0 | 0 | — |
case-12 | pass→pass | 4,840 | 3,456 | -29% | 1 | 1 | 0% | 884 | 2,141 | +142% | 0 | 0 | — |
case-13 | pass→pass | 10,581 | 10,028 | -5% | 1 | 1 | 0% | 1,877 | 3,359 | +79% | 0 | 0 | — |
case-14 | pass→pass | 5,166 | 4,396 | -15% | 1 | 1 | 0% | 1,079 | 2,367 | +119% | 0 | 0 | — |
case-15 | pass→pass | 3,661 | 5,062 | +38% | 1 | 1 | 0% | 619 | 2,396 | +287% | 0 | 0 | — |
case-16 | pass→pass | 16,820 | 13,684 | -19% | 1 | 1 | 0% | 2,838 | 3,850 | +36% | 0 | 0 | — |
case-17 | pass→pass | 3,108 | 3,489 | +12% | 1 | 1 | 0% | 262 | 1,946 | +643% | 0 | 0 | — |
case-18 | pass→pass | 7,378 | 3,057 | -59% | 1 | 1 | 0% | 1,209 | 2,029 | +68% | 0 | 0 | — |
case-19 | pass→pass | 10,134 | 1,986 | -80% | 1 | 1 | 0% | 1,884 | 1,824 | -3% | 0 | 0 | — |
case-20 | pass→pass | 6,511 | 4,561 | -30% | 1 | 1 | 0% | 1,033 | 2,317 | +124% | 0 | 0 | — |
case-21 | pass→pass | 7,703 | 4,295 | -44% | 1 | 1 | 0% | 1,216 | 1,987 | +63% | 0 | 0 | — |
case-22 | pass→pass | 9,057 | 6,762 | -25% | 1 | 1 | 0% | 1,427 | 2,745 | +92% | 0 | 0 | — |
case-23 | pass→pass | 9,152 | 5,506 | -40% | 1 | 1 | 0% | 1,656 | 2,407 | +45% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.