Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

📙 You will learn

How to generate a Burp Suite report and upload it to ThreadFix.

Prerequisites

Audience: IT Professional
Difficulty: Basic
Time needed: Approximately 10 minutes
Tools required: N/A

Generate Results

  1. After launching BURP Suite Professional, there are three options for obtaining results to generate a report. Select any of the available options below:

    • Temporary project

    • New project on disk

    • Open existing project

  2. From the configuration selection screen, select Use Burp defaults and click the Start Burp button.

  3. Click the Proxy tab and select the Options sub-tab. Confirm the Proxy is running.

  4. Open Google Chrome and set the Proxy through the Settings tab. Set the port to the one used in BURP:

  5. From the Proxy tab, select the Intercept sub-tab and select the Interceptor is off button setting:

  6. Navigate to the Target in Chrome, select the Target tab, select the URL in Burp,and perform the following procedures:

    1. Run Spider this host

    2. Run the Actively scan this host

    3. Run the Passively scan this host

  7. Select the findings in the Issues pane and choose Report selected issues.

  8. Select XML for the report format.

  9. Select Next until the reporting wizard asks to save the file, then save it to the desired directory.

Upload Results

  1. After generating the report, log in to ThreadFix and navigate to the Teams tab view, within the Portfolio page. Expand the Team the report will be uploaded to.

  2. After picking one of the Team's Applications, select Upload Scan and drag the report into the pane.

  3. Once ThreadFix has finished processing the report, the results can be viewed on the Application's page view.

Table of Contents

Table of Contents