Burp Suite sits between your browser and the target. Everything passes through it first. That's the whole premise, and once it clicks, most of the tool explains itself from there.
I've been working through the Jr. Penetration Tester path on TryHackMe, and Burp Suite is the thing I keep reaching for. Not because it's flashy, but because it turns "there's probably a bug in here somewhere" into "here's the exact request that proves it."
What's Actually in the Box
Three editions exist. Community is free and fine for learning, but it strips out automation. Professional adds the scanner and the Intruder speed you actually want once you're testing anything beyond a lab box. Enterprise is built for running scans across dozens of applications at once, not really relevant at this stage.
The features that matter day to day: Proxy intercepts and lets you modify HTTP/S traffic before it ever reaches the server. Repeater takes one request and lets you resend it, tweaked, as many times as you want. Intruder automates the repetitive part, brute force, parameter fuzzing, anything you'd otherwise do by hand a thousand times over. Sequencer checks how random your session tokens actually are. Comparer lines two responses or hashes up side by side and shows exactly what changed. Decoder handles the encoding gymnastics every web app seems to need somewhere.
None of these are impressive on their own. What matters is how they chain together.
IDOR: When the URL Is the Vulnerability
The clearest example from my labs was an Insecure Direct Object Reference. Picture a support ticket system where the ticket number sits right in the URL:
http://10.10.185.10/support/ticket/NUMBERIf the app checks that you're logged in but never checks whether the ticket actually belongs to you, that number becomes the entire access control.
First step was just watching the traffic. Logged in, opened a ticket, caught the request in Proxy:
GET /support/ticket/123 HTTP/1.1
Host: 10.10.185.10
Cookie: session=eyJ0b2tlbiI6IjoiMzUyNTQ5ZjgThen the obvious test: change the number, nothing else.
GET /support/ticket/124 HTTP/1.1It worked. Someone else's ticket, my session cookie. That's the confirmation, IDOR present.
From there it stops being manual. Sent the request to Intruder, marked the ticket number as the payload position (/support/ticket/§NUMBER§), pointed it at a range of 1000-2000, and let it run. What came back was a pile of other users' data, pulled one request at a time without ever touching their accounts.
That's the part that makes IDOR worth taking seriously. It's not clever. It's a missing check, and the exploit is just asking for the next number.
Sequencer: How Random Is Random
Session tokens only do their job if they can't be guessed. Low entropy means an attacker doesn't need to steal a session, they can predict one.
I grabbed a batch of tokens off the admin login and pointed Sequencer at them. It came back with 117 bits of entropy and a 99% confidence rating, based on a sample of 10,539 tokens. That's a strong result: high randomness, low odds of a token ever repeating or being guessed inside a realistic timeframe.
Flip that number lower, and the same analysis turns into an attack plan instead of a reassurance. Predictable tokens mean you don't need credentials, you need patience and a way to enumerate the pattern.
Comparer: Finding the Crack in a Hash
The last piece I worked through was hash comparison. Grabbed a handful of hashed passwords out of an intercepted login flow and ran them through Comparer to see where they diverged.
Small, structured differences between hashes are often the tell for a weak or outdated hashing algorithm, the kind that makes brute-forcing realistic instead of theoretical. Comparer doesn't crack anything itself. It just shows you where to look, which turns out to be most of the work.
Where This Goes Next
Burp Suite ended up being less about the tool itself and more about the habit it builds: intercept first, assume nothing, verify what the client sends against what the server actually checks.
Next up: Wireshark for packet-level analysis, Metasploit for the exploitation side, John the Ripper for password cracking, privilege escalation once I'm past initial access, and Nmap to tie the recon side together properly.
More on each of those as I get through them.