Burp Suite User Forum

Create new post

Fuzz APIs ?

Dhaval | Last updated: May 10, 2018 12:04PM UTC

Do burp is having any extension which can help in Pen test of APIs ? Like another tool API fuzzer ? along with Intruder what else can be used to do API pen test automatically ?

Liam, PortSwigger Agent | Last updated: May 10, 2018 12:43PM UTC

Hi Dhaval Thanks for your message. Burp can test any REST API endpoint, provided you can use a normal client for that endpoint to generate normal traffic. The process is to proxy the client's traffic through Burp and then test it in the normal way, including automated testing with Burp Scanner. - https://support.portswigger.net/customer/portal/articles/2898121-using-burp-to-enumerate-a-rest-api - https://support.portswigger.net/customer/portal/articles/2898216-using-burp-to-test-a-rest-api There are extensions to assist with API testing, but not in the manner you describe, e.g. - https://portswigger.net/bappstore/6bf7574b632847faaaa4eb5e42f1757c Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.