As of December 31st, 2023 ThreadFix 2.X has reached End of Life and is no longer supported. For any further information please contact the Success and Implementation team.

BURP Suite

You will learn

How to generate a Burp Suite report and upload it to ThreadFix.

Prerequisites

Audience: IT Professional
Difficulty: Basic
Time needed: Approximately 10 minutes
Tools required: N/A

Generate Results

  1. After launching BURP Suite Professional, there are three options for obtaining results to generate a report. Select any of the available options below:

    • Temporary project

    • New project on disk

    • Open existing project

       

  2. Select Use Burp defaults and select Start Burp:

     

  3. Select the Proxy tab and select the Options tab. Make sure the Proxy is running:



  4. Open Chrome and set the proxy through the settings tab. Set the port to the one used in BURP:

     

  5. Select Intercept tab and set turn the Interceptor off:

  6. Navigate to the Target in Chrome, select the Target tab and then select the URL in Burp:

    1. Run the Spider

    2. Run the Actively scan this host

    3. Run the Passively scan this host


       

  7. Select the findings in the Issues Pane and select Report selected issues:



  8. Select XML for the report format and check the Base64 box below it:



  9. Select Next until the wizards asks to save the file and save it to the desired directory:

 

Upload Results

  1. After generating the report, log in to ThreadFix and navigate to the Teams view, within the Portfolio page. Expand the Team the report will be uploaded to.

     

  2. After picking one of the Team's Application, select Upload Scan and drag the report into the Pane:

     

  3. Once ThreadFix has finish processing the report, the results can be viewed on the Application's view:

www.threadfix.it | www.coalfire.com
Copyright © 2024 Coalfire. All rights reserved.

This Information Security Policy is CoalFire - Public: Distribution of this material is not limited.