Burp Suite User Forum

Create new post

Testing web services

Karthik | Last updated: Jun 28, 2017 02:22PM UTC

Is burp capable of testing web services - can all test cases defined in OWASP cheat sheet be tested ? https://www.owasp.org/index.php/Web_Service_Security_Testing_Cheat_Sheet

PortSwigger Agent | Last updated: Jun 28, 2017 02:24PM UTC

Hi Karthik, Burp can certainly help you perform all those test cases. Some tests require manual work by the tester. Burp Active Scan can cover some of the issues. For example, insertion points in JSON and XML are identified and attack payloads for issues like SQL injection are attempted. There are also extensions in the BApp store that help with discovery of particular types of web service, e.g. Wsdler, Swagger parser. Please let us know if you need any further assistance.

Burp User | Last updated: Jul 26, 2018 08:17PM UTC

How to test web services using burp suite and what is the procedure for it and what are the best practices?

PortSwigger Agent | Last updated: Jul 27, 2018 11:22AM UTC

There's some information on the Support Center: "Using Burp to Test a REST API":https://support.portswigger.net/customer/portal/articles/2898216-using-burp-to-test-a-rest-api You can use a similar approach to test SOAP web service as well.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.