Installation and first launch of Burp Suite Community
Burp Suite Community Edition is free and covers everything you need for CTF: Proxy with interception, Repeater, Intruder (with speed limit), Decoder, Comparer. The installer swings with portswigger.net and already includes Java - you do not need to put separately. Read more in our article about creating ctf tasks.
First start: Temporary project → Use Burp defaults → Start Burp. For CTF, saving the project to disk is meaningless - the task is solved in one session.
For web CTF tasks, the Community is enough with a reserve. Full-speed Intruder and active Scanner are the only major limitations, and on CTFs with small dictionaries and manual testing, they are not critical.
Configure Burp Suite proxy and browser connection
Burp works as an intercepting proxy server. In fact, it is Adversary-in-the-Middle (T1557 by MITRE ATT&CK), only apply it to your own traffic in a controlled environment. By default Burp listens on 127.0.0.1:8080. The browser must be sent through this proxy so that each HTTP/HTTPS request passes through Burp.
Quick path: Burp browser built-in
Burp includes a built-in Chromium with a pre-installed CA certificate. Proxy → Intercept → Open Browser — and you can immediately intercept HTTPS without fiddling with certificates. For a quick solution to a single CTF, this is the shortest way. Less – it is inconvenient to switch between conventional surfing and work through a proxy.
FoxyProxy + Firefox for permanent work
For regular participation in the CTF, the Firefox + FoxyProxy bundle is more convenient. Create a “Burp” profile and switch between a proxy and a direct connection with a single click. Without FoxyProxy each time you will have to climb into Firefox → Settings → Basic → Network Options → Manual configuration of the proxy. Already on the third task it begins to piss.
Configure FoxyProxy: install the extension from addons.mozilla.org, create a profile with Title "Burp", Proxy Type - HTTP, Hostname - 127.0.0.1, Port — 8080. Activate the profile - the icon will change color, the traffic will go through Burp.
Installing a CA certificate for HTTPS
Without a CA certificate, Burp will not decrypt HTTPS traffic, and each site will show an SSL error. Built-in browser – certificate is already in place. For Firefox:
Launch Burp, activate proxy via FoxYProxy
Open http://burp/ in Firefox — the Burp page with the CA Certificate button will be downloaded
Download the file cacert.der
Firefox → Settings → Privacy and Protection → Certificates → Certificate View → Certification Centers → Import
Select cacert.der, note “Trust in website identification” → OK
Check: Open any HTTPS site via proxy. There are no warnings, and in Burp → Proxy → HTTP History there is a request - the interception of browser traffic works.
A typical mistake of beginners: forget to set the certificate and kill half an hour on “why nothing loads”. The second most frequent is not to disable the browser cache. The answers come from the cache, bypassing Burp, and you sit thinking Burp broke down.
Interception of Burp Suite: Proxy and HTTP History
Proxy is the core of the whole work. Here there is an interception of Burp Suite requests, from here the data goes to the other tools.
HTTP History: Passive Intelligence Application
Before you intercept something, just go around the target application with the Intercept off (Intercept is off button). All requests and responses are recorded in Proxy → HTTP History. It is a passive phase, and it is a mistake to pass it. You will see:
All the endpoints of the application, including background API calls, which are not visible in the browser
Parameters in query string, POST bodies, JSON payloads and cookies
Custom headlines like X-Role, X-Admin, Authorization – hints to access logic
Session token format: opaque string, Base64-blob or JWT
Sorting on Status Code instantly displays on interesting: 302-redirects (where does it redirect?) and 403-bans (what do they hide?). In CTF 403 often means “there is something valuable here, but you are not allowed” – it is such endpoints that should be picked first.
Intercept: stopping the flight request
Enable Intercept is on — each outgoing request is frozen in Burp before your decision. Three buttons:
Forward – send a request to the server (after edits or without)
Drop - destroy the request, it will not reach the server
Action – send a request to Repeater, Intruder or other tool
The moment that Russian-language guides usually miss: enable Intercept only before a specific action (pressing a button, submitting a form), and not for general surfing. Otherwise, you will press Forward dozens of times on background requests to analytics and CDN, lose focus and miss the desired request. Intercept OFF for mapping application, Intercept ON for point modification.
Server response interception
A function that almost all Russian-language guides are silent about: you can intercept not only requests, but also answers. Proxy → Options → Intercept Server Responses — enable. Burp will stop the server’s response before it gets into the browser. Why: remove JavaScript verification, change admin: false on admin: true in JSON response, spy on hidden data before the page renders. On the CTF, I use this less often than intercepting requests, but when necessary, I save a lot of time.
Scope: Noise Filtration
CTF-TASKS work on a specific host. HTTP History is quickly clogged with CDN, analytics, and external resources. Right click on the request to the target host → Add to scope. In HTTP History, enable the Show only in-scope items filter, and in Proxy → Options, activate “And URL is in target scope”. Now Intercept catches only requests to your goal, not all the trash.
HTTP query modification: bypassing client validation
This pattern is found in the vast majority of web CTF tasks. The form on the page restricts input through JavaScript: readonly fields, allowable file types, numerical ranges. JavaScript is running in your browser, and there may not be any checks on the server. According to the documents, it is impossible. In practice, elementary.
A classic example from PortSwigger’s Web Security Academy is a price manipulation lab. You have $100 on the account, the jacket costs $1337. The price cannot be changed through the interface. Through Burp:
POST /cart HTTP/2
Host: target.web-security-academy.net
Content-Type: application/x-www-form-urlencoded
productId=2&redir=PRODUCT&quantity=1&price=1
Original meaning price=133700 (in cents) replaced by price=1. Forward - in a basket jacket for 1 cent. The interface did not allow, but Burp Suite works at HTTP level, below JavaScript.
Algorithm for any task with customer validation:
Fill out the form with valid data – let JavaScript miss send
Enable Intercept is on right before clicking Submit
When the request appears in Burp, change the desired parameters: role=user → role=admin, filename="photo.jpg" → filename="shell.php", quantity=1 → quantity=-1
Forward – the server will get your version, JavaScript will not know about it
According to MITRE ATT&CK, modification of queries to the web application - technique Exploit Public-Facing Application (T1190, Initial Access). This is what CTF tasks model.
Burp Suite Repeater: manual testing in web CTF tasks
Repeater is a tool in which you will spend the most time when solving a CTF. Send the same query with different parameters, instantly see the server response. No re-interception, no switching tabs.
Send: right-click on any request in HTTP History or Intercept → Send to Repeater (Ctrl+R). On the left is the editable request, the answer on the right. Send → received a response. Changed the →Send option again. Simple and fast.
Typical CTF scenarios in Repeater
IDOR (Insecure Direct Object Reference). Intercept GET /api/user/1337/profile. In Repeater replace 1337 on 1, 2, 3 and send each option. Does the server give data to other people's users without verifying authorization? This IDOR is one of the most frequent vulnerabilities in the CTF (OWASP A01:2021 Broken Access Control). On real projects, by the way, too there is a frightening often.
SQL Injection. Request contains id=5. In Repeater try id=5' If the response size or status code has changed, it is an injection marker (OWASP A03:2021 Injection). Single quotation does not give a visible difference? Try the comments (--, #), logical designs (' OR '1'='1) or timing injections (SLEEP()). Further: id=5' OR 1=1--, id=5' UNION SELECT null,null--. Repeater allows you to iterate the payloads in seconds.
Manipulation of cookies and JWT. Copy the request with session cookie in Repeater. Cookie looks like Base64 – decode through Decoder (or directly in Inspector Repeater panel). Often inside is detected JSON with the field "admin": false or "role": "user". Change the value, encode back, paste into cookies and send. This technique is related to the Steal Web Session Cookie (T1539) and Web Cookies (T1606.001) by MITRE ATT&CK.
What to look at in each answer:
Status code: 200 → success, 403 → close but not allowed, 302 → redirection (where?)
Content-Length: the difference in size between options is often the key to the correct payload
Body of reply: look for the flag (flag{...}, CTF{...}), SQL errors with table names, file paths in error messages
Burp Suite Intruder: automatic overtaking of parameters
Intruder automates the sending of many request options. In Community Edition, the speed is limited (throttling between queries), but for CTFs with small dictionaries is enough.
Setting up an attack
Send a request to Intruder: right-click → Send to Intruder (Ctrl+I)
Positions tab: Burp will automatically place markers § around the intended parameters. Click Clear §, then select a specific option and Add §
POST /login HTTP/1.1
Host: target.ctf.local
Content-Type: application/x-www-form-urlencoded
username=admin&password=§password123§
Payloads tab: Download the list of values — wordlists from SecLists, numerical sequences or own list
Start attack
Four types of attacks:
Type When to use Example in CTF
Sniper One parameter, one wordlist Overkill ID: /user/§1§/profile
Battering Ram One value in all positions The same token in several titles
Pitchfork Different lists synchronously (line 1 from list A + line 1 from list B) Login
assword pairs from leak
Cluster Bomb All combinations of all lists Complete overkill login + password
For CTF, most often you need Sniper (too much of a single parameter) and occasionally Cluster Bomb (brutfors of the login/password pair). Cluster Bomb with two lists of 100 values generates 10 000 queries - in the Community Edition it will take time, but for CTFs usually has lists of 20-50 values.
According to MITRE ATT&CK, the selection of passwords through Intruder is a Password Guessing technique (T1110.001, Credential Access).
Analysis of results
Sort by column Length. All answers – 403 to 250 bytes, and one – 200 to 1200 bytes? This is your result. The same reception with Status code: one 302-redirect among the hundreds of 401 is the correct password indicator. I usually immediately click on the title of the Length column – the anomaly pops up instantly.
Decoder and Comparer: Encoding and Comparison in CTF
Decoder for data decryption
In CTF, there are constantly coded data: Base64-tokens, URL-encoded parameters, hex-values, sometimes encoding chains. Decoder converts to the fly:
Base64 Decode/Encode – Disassemble a cookie or assemble a modified token. Example: YWRtaW46dHJ1ZQ== → admin:true
URL Decode – read %3Cscript%3Ealert(1)%3C%2Fscript%3E How <script>alert(1)</script>
HTML Decode – to decode HTML-entities into readable text
Hex → ASCII — decrypt hex dumps
Decoding chains are a frequent CTF reception: the value is first Base64, then URL-encoded, then again Base64. Such a doll. In Decoder, you can click Smart Decode – Burp will try to automatically define encoding – or select the format sequentially manually.
Comparer to find differences
Comparer pobytovo compares two responses or requests. The two answers look visually the same, but one contains a hidden parameter or differs on the symbol - do not notice with your eyes, Comparer will show. Submit both answers from Repeater to Comparer (right-click →Send to Comparer) and press Words or Bytes – Burp will highlight the differences. In CTF, it helps to find the difference between the “right” and the “wrong” answer when both return 200 OK.
Step-by-Step Workflow for Web CTF Tasks
The order of action that works on most jeopardy web-tasks:
Intelligence. Open the push in the browser via Burp proxy with Intercept OFF. Click all pages, forms, buttons. 3-5 minutes to learn HTTP History — do not spare this time.
Scope. Add a Taska host to Scope, enable the Show only in-scope filter — remove the noise.
Map of the endpoints. View all URLs in HTTP History. /api/... calls, parameters id, role, token, admin, custom headlines – record suspicious.
Repeater for manual dough. Found a request with interesting parameters — Ctrl+R, start changing the values. Check the IDOR, change the roles, try special symbols for SQL injections.
Intercept to circumvent validation. The form does not let the desired characters or limit the file type - fill in valid, enable Intercept ON, replace before sending.
Intruder for overkill. You need to choose an ID, password or hidden parameter – Ctrl+I, download wordlist, sort results by Length.
Decoder for encoding. Incomprehensible cookie or token – copy to Decoder, try Smart Decode or Base64 manually.
Comparer for comparison. The two answers look the same – send both to Comparer, look for a byte difference.
Burp Suite Community Edition is free and covers everything you need for CTF: Proxy with interception, Repeater, Intruder (with speed limit), Decoder, Comparer. The installer swings with portswigger.net and already includes Java - you do not need to put separately. Read more in our article about creating ctf tasks.
First start: Temporary project → Use Burp defaults → Start Burp. For CTF, saving the project to disk is meaningless - the task is solved in one session.
For web CTF tasks, the Community is enough with a reserve. Full-speed Intruder and active Scanner are the only major limitations, and on CTFs with small dictionaries and manual testing, they are not critical.
Configure Burp Suite proxy and browser connection
Burp works as an intercepting proxy server. In fact, it is Adversary-in-the-Middle (T1557 by MITRE ATT&CK), only apply it to your own traffic in a controlled environment. By default Burp listens on 127.0.0.1:8080. The browser must be sent through this proxy so that each HTTP/HTTPS request passes through Burp.
Quick path: Burp browser built-in
Burp includes a built-in Chromium with a pre-installed CA certificate. Proxy → Intercept → Open Browser — and you can immediately intercept HTTPS without fiddling with certificates. For a quick solution to a single CTF, this is the shortest way. Less – it is inconvenient to switch between conventional surfing and work through a proxy.
FoxyProxy + Firefox for permanent work
For regular participation in the CTF, the Firefox + FoxyProxy bundle is more convenient. Create a “Burp” profile and switch between a proxy and a direct connection with a single click. Without FoxyProxy each time you will have to climb into Firefox → Settings → Basic → Network Options → Manual configuration of the proxy. Already on the third task it begins to piss.
Configure FoxyProxy: install the extension from addons.mozilla.org, create a profile with Title "Burp", Proxy Type - HTTP, Hostname - 127.0.0.1, Port — 8080. Activate the profile - the icon will change color, the traffic will go through Burp.
Installing a CA certificate for HTTPS
Without a CA certificate, Burp will not decrypt HTTPS traffic, and each site will show an SSL error. Built-in browser – certificate is already in place. For Firefox:
Launch Burp, activate proxy via FoxYProxy
Open http://burp/ in Firefox — the Burp page with the CA Certificate button will be downloaded
Download the file cacert.der
Firefox → Settings → Privacy and Protection → Certificates → Certificate View → Certification Centers → Import
Select cacert.der, note “Trust in website identification” → OK
Check: Open any HTTPS site via proxy. There are no warnings, and in Burp → Proxy → HTTP History there is a request - the interception of browser traffic works.
A typical mistake of beginners: forget to set the certificate and kill half an hour on “why nothing loads”. The second most frequent is not to disable the browser cache. The answers come from the cache, bypassing Burp, and you sit thinking Burp broke down.
Interception of Burp Suite: Proxy and HTTP History
Proxy is the core of the whole work. Here there is an interception of Burp Suite requests, from here the data goes to the other tools.
HTTP History: Passive Intelligence Application
Before you intercept something, just go around the target application with the Intercept off (Intercept is off button). All requests and responses are recorded in Proxy → HTTP History. It is a passive phase, and it is a mistake to pass it. You will see:
All the endpoints of the application, including background API calls, which are not visible in the browser
Parameters in query string, POST bodies, JSON payloads and cookies
Custom headlines like X-Role, X-Admin, Authorization – hints to access logic
Session token format: opaque string, Base64-blob or JWT
Sorting on Status Code instantly displays on interesting: 302-redirects (where does it redirect?) and 403-bans (what do they hide?). In CTF 403 often means “there is something valuable here, but you are not allowed” – it is such endpoints that should be picked first.
Intercept: stopping the flight request
Enable Intercept is on — each outgoing request is frozen in Burp before your decision. Three buttons:
Forward – send a request to the server (after edits or without)
Drop - destroy the request, it will not reach the server
Action – send a request to Repeater, Intruder or other tool
The moment that Russian-language guides usually miss: enable Intercept only before a specific action (pressing a button, submitting a form), and not for general surfing. Otherwise, you will press Forward dozens of times on background requests to analytics and CDN, lose focus and miss the desired request. Intercept OFF for mapping application, Intercept ON for point modification.
Server response interception
A function that almost all Russian-language guides are silent about: you can intercept not only requests, but also answers. Proxy → Options → Intercept Server Responses — enable. Burp will stop the server’s response before it gets into the browser. Why: remove JavaScript verification, change admin: false on admin: true in JSON response, spy on hidden data before the page renders. On the CTF, I use this less often than intercepting requests, but when necessary, I save a lot of time.
Scope: Noise Filtration
CTF-TASKS work on a specific host. HTTP History is quickly clogged with CDN, analytics, and external resources. Right click on the request to the target host → Add to scope. In HTTP History, enable the Show only in-scope items filter, and in Proxy → Options, activate “And URL is in target scope”. Now Intercept catches only requests to your goal, not all the trash.
HTTP query modification: bypassing client validation
This pattern is found in the vast majority of web CTF tasks. The form on the page restricts input through JavaScript: readonly fields, allowable file types, numerical ranges. JavaScript is running in your browser, and there may not be any checks on the server. According to the documents, it is impossible. In practice, elementary.
A classic example from PortSwigger’s Web Security Academy is a price manipulation lab. You have $100 on the account, the jacket costs $1337. The price cannot be changed through the interface. Through Burp:
POST /cart HTTP/2
Host: target.web-security-academy.net
Content-Type: application/x-www-form-urlencoded
productId=2&redir=PRODUCT&quantity=1&price=1
Original meaning price=133700 (in cents) replaced by price=1. Forward - in a basket jacket for 1 cent. The interface did not allow, but Burp Suite works at HTTP level, below JavaScript.
Algorithm for any task with customer validation:
Fill out the form with valid data – let JavaScript miss send
Enable Intercept is on right before clicking Submit
When the request appears in Burp, change the desired parameters: role=user → role=admin, filename="photo.jpg" → filename="shell.php", quantity=1 → quantity=-1
Forward – the server will get your version, JavaScript will not know about it
According to MITRE ATT&CK, modification of queries to the web application - technique Exploit Public-Facing Application (T1190, Initial Access). This is what CTF tasks model.
Burp Suite Repeater: manual testing in web CTF tasks
Repeater is a tool in which you will spend the most time when solving a CTF. Send the same query with different parameters, instantly see the server response. No re-interception, no switching tabs.
Send: right-click on any request in HTTP History or Intercept → Send to Repeater (Ctrl+R). On the left is the editable request, the answer on the right. Send → received a response. Changed the →Send option again. Simple and fast.
Typical CTF scenarios in Repeater
IDOR (Insecure Direct Object Reference). Intercept GET /api/user/1337/profile. In Repeater replace 1337 on 1, 2, 3 and send each option. Does the server give data to other people's users without verifying authorization? This IDOR is one of the most frequent vulnerabilities in the CTF (OWASP A01:2021 Broken Access Control). On real projects, by the way, too there is a frightening often.
SQL Injection. Request contains id=5. In Repeater try id=5' If the response size or status code has changed, it is an injection marker (OWASP A03:2021 Injection). Single quotation does not give a visible difference? Try the comments (--, #), logical designs (' OR '1'='1) or timing injections (SLEEP()). Further: id=5' OR 1=1--, id=5' UNION SELECT null,null--. Repeater allows you to iterate the payloads in seconds.
Manipulation of cookies and JWT. Copy the request with session cookie in Repeater. Cookie looks like Base64 – decode through Decoder (or directly in Inspector Repeater panel). Often inside is detected JSON with the field "admin": false or "role": "user". Change the value, encode back, paste into cookies and send. This technique is related to the Steal Web Session Cookie (T1539) and Web Cookies (T1606.001) by MITRE ATT&CK.
What to look at in each answer:
Status code: 200 → success, 403 → close but not allowed, 302 → redirection (where?)
Content-Length: the difference in size between options is often the key to the correct payload
Body of reply: look for the flag (flag{...}, CTF{...}), SQL errors with table names, file paths in error messages
Burp Suite Intruder: automatic overtaking of parameters
Intruder automates the sending of many request options. In Community Edition, the speed is limited (throttling between queries), but for CTFs with small dictionaries is enough.
Setting up an attack
Send a request to Intruder: right-click → Send to Intruder (Ctrl+I)
Positions tab: Burp will automatically place markers § around the intended parameters. Click Clear §, then select a specific option and Add §
POST /login HTTP/1.1
Host: target.ctf.local
Content-Type: application/x-www-form-urlencoded
username=admin&password=§password123§
Payloads tab: Download the list of values — wordlists from SecLists, numerical sequences or own list
Start attack
Four types of attacks:
Type When to use Example in CTF
Sniper One parameter, one wordlist Overkill ID: /user/§1§/profile
Battering Ram One value in all positions The same token in several titles
Pitchfork Different lists synchronously (line 1 from list A + line 1 from list B) Login
Cluster Bomb All combinations of all lists Complete overkill login + password
For CTF, most often you need Sniper (too much of a single parameter) and occasionally Cluster Bomb (brutfors of the login/password pair). Cluster Bomb with two lists of 100 values generates 10 000 queries - in the Community Edition it will take time, but for CTFs usually has lists of 20-50 values.
According to MITRE ATT&CK, the selection of passwords through Intruder is a Password Guessing technique (T1110.001, Credential Access).
Analysis of results
Sort by column Length. All answers – 403 to 250 bytes, and one – 200 to 1200 bytes? This is your result. The same reception with Status code: one 302-redirect among the hundreds of 401 is the correct password indicator. I usually immediately click on the title of the Length column – the anomaly pops up instantly.
Decoder and Comparer: Encoding and Comparison in CTF
Decoder for data decryption
In CTF, there are constantly coded data: Base64-tokens, URL-encoded parameters, hex-values, sometimes encoding chains. Decoder converts to the fly:
Base64 Decode/Encode – Disassemble a cookie or assemble a modified token. Example: YWRtaW46dHJ1ZQ== → admin:true
URL Decode – read %3Cscript%3Ealert(1)%3C%2Fscript%3E How <script>alert(1)</script>
HTML Decode – to decode HTML-entities into readable text
Hex → ASCII — decrypt hex dumps
Decoding chains are a frequent CTF reception: the value is first Base64, then URL-encoded, then again Base64. Such a doll. In Decoder, you can click Smart Decode – Burp will try to automatically define encoding – or select the format sequentially manually.
Comparer to find differences
Comparer pobytovo compares two responses or requests. The two answers look visually the same, but one contains a hidden parameter or differs on the symbol - do not notice with your eyes, Comparer will show. Submit both answers from Repeater to Comparer (right-click →Send to Comparer) and press Words or Bytes – Burp will highlight the differences. In CTF, it helps to find the difference between the “right” and the “wrong” answer when both return 200 OK.
Step-by-Step Workflow for Web CTF Tasks
The order of action that works on most jeopardy web-tasks:
Intelligence. Open the push in the browser via Burp proxy with Intercept OFF. Click all pages, forms, buttons. 3-5 minutes to learn HTTP History — do not spare this time.
Scope. Add a Taska host to Scope, enable the Show only in-scope filter — remove the noise.
Map of the endpoints. View all URLs in HTTP History. /api/... calls, parameters id, role, token, admin, custom headlines – record suspicious.
Repeater for manual dough. Found a request with interesting parameters — Ctrl+R, start changing the values. Check the IDOR, change the roles, try special symbols for SQL injections.
Intercept to circumvent validation. The form does not let the desired characters or limit the file type - fill in valid, enable Intercept ON, replace before sending.
Intruder for overkill. You need to choose an ID, password or hidden parameter – Ctrl+I, download wordlist, sort results by Length.
Decoder for encoding. Incomprehensible cookie or token – copy to Decoder, try Smart Decode or Base64 manually.
Comparer for comparison. The two answers look the same – send both to Comparer, look for a byte difference.