Using Burp for content and file discovery

For this module, we are going to use OWASP BWA and do a discovery of all the files and folders in the set of applications available. We will see how to configure and set up the necessary parameters over Burp to perform a content discovery. 

Start the OWASP BWA VM and note down the IP address, access the application in a browser, and check your sitemap in Burp Suite. It should look something like this:

Go ahead and right-click on the URL address, then select Engagement tools, and then click on Discover content. It will show you the different sets of parameters that you can specify to begin the automated ...

Get Hands-On Application Penetration Testing with Burp Suite now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.