The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Testing web services

Karthik | Last updated: Jun 28, 2017 02:22PM UTC

Is burp capable of testing web services - can all test cases defined in OWASP cheat sheet be tested ? https://www.owasp.org/index.php/Web_Service_Security_Testing_Cheat_Sheet

PortSwigger Agent | Last updated: Jun 28, 2017 02:24PM UTC

Hi Karthik, Burp can certainly help you perform all those test cases. Some tests require manual work by the tester. Burp Active Scan can cover some of the issues. For example, insertion points in JSON and XML are identified and attack payloads for issues like SQL injection are attempted. There are also extensions in the BApp store that help with discovery of particular types of web service, e.g. Wsdler, Swagger parser. Please let us know if you need any further assistance.

Burp User | Last updated: Jul 26, 2018 08:17PM UTC

How to test web services using burp suite and what is the procedure for it and what are the best practices?

PortSwigger Agent | Last updated: Jul 27, 2018 11:22AM UTC