Burp Suite User Forum

Create new post

How can I test native application through Burp suite ?

Dhaval | Last updated: Apr 23, 2018 07:31AM UTC

Hi, We have one licence of Burp Suite. I want to purchase another for my current project. Which involves API, Native and Web application. So my question is Burp can test native application ? Do we have some useful guide for that ? Please dont provide link for mobile web application. Also How to Pen test APIs in Burp ? If burp is fitting fine with above requirement then I can talk to my managers. But I need to know how ? at first place.

PortSwigger Agent | Last updated: Apr 23, 2018 08:21AM UTC

Hi Dhaval, You can test a native application by configuring the application proxy settings. Some use the system proxy settings; some have their own. If the app does not allow a proxy to be configured, you can use this workaround: - https://support.portswigger.net/customer/portal/articles/2899081-using-burp-s-invisible-proxy-settings-to-test-a-non-proxy-aware-thick-client-application For testing an API there are a few approaches. If you have a client application you can use Burp as a proxy and intercept the requests. Alternatively, if you have a WSDL file or an OpenAPI definition, there are extensions to parse those files. There's some more information here: - https://support.portswigger.net/customer/portal/articles/2898216-using-burp-to-test-a-rest-api Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.