How to Intercept Requests & Modify Responses With Burp Suite

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ม.ค. 2025

ความคิดเห็น • 142

  • @ashleypursell9702
    @ashleypursell9702 4 ปีที่แล้ว +27

    this guy has the best voice for this holly shit hahaha. gives off a vibe where its like dont worry ill teach you what you need to know just enjoy

  • @rolikaseventysix
    @rolikaseventysix 6 ปีที่แล้ว +86

    What a cool voice dude

    • @WebDevwithMatt
      @WebDevwithMatt  6 ปีที่แล้ว +7

      Thanks for saying so. Too kind.

  • @MREditz170
    @MREditz170 2 ปีที่แล้ว +2

    Hes so calm its so wholesome

  • @mary6305
    @mary6305 4 ปีที่แล้ว +9

    Excellent tutorial!! Thank you for this! Please make more on BurpSuite! And great voice btw :D

  • @jackoneil1000
    @jackoneil1000 4 ปีที่แล้ว +2

    I love your voice, you are the Bob Ross of IT

  • @faithdouglas589
    @faithdouglas589 2 ปีที่แล้ว +4

    Excellent tutorial, but any other tool you can suggest asides from Burp suite to intercept requests

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว +1

      Three you can try are YAP (www.zaproxy.org/), mitmproxy (mitmproxy.org/), and Charles (www.charlesproxy.com/). I believe Charles is macOS only.

  • @NarendraSingh-oy1mc
    @NarendraSingh-oy1mc 4 ปีที่แล้ว +3

    Awesome...I was looking for this type of video...Thanks

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      Glad to hear that it helped you out.

  • @breezebee6568
    @breezebee6568 4 ปีที่แล้ว +1

    I watched this video million times,🙏😊it's so cool , I loved it !!!!!

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      Very kind of you to say so. Thank you.

  • @manhu8900
    @manhu8900 3 ปีที่แล้ว +1

    I try the tutorial, but it's reset when page refreshed.
    I mean, it's not change.

  • @toki3204
    @toki3204 3 ปีที่แล้ว

    Your voice is so fucking amazing, so calming and you just WANT TO listen to it

  • @andrewp7497
    @andrewp7497 9 หลายเดือนก่อน

    Great thanks, helped me understand what I needed to return a different response, cheers.

  • @roedor2802
    @roedor2802 5 หลายเดือนก่อน

    My youtube was in autoplay and this video scared the shit out of me. Great content tho, it helped me a lot

  • @poorvadharmadhikari3841
    @poorvadharmadhikari3841 5 ปีที่แล้ว +3

    Can you make more of these. Maybe something on intercepting and modifying the payloads

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว +4

      Sure can. Thanks for letting me know that you're keen. I'll need a little bit of time to plan out the series, but I'll make it happen.

    • @AbhishekSharma-vr3ss
      @AbhishekSharma-vr3ss ปีที่แล้ว

      Hiiii

  • @nogoodhacker6944
    @nogoodhacker6944 3 ปีที่แล้ว

    Thank you man!
    Wondered how to modify response since i already knew how to modify requests
    Extremely helpful Thnx Once again!!!

  • @mizo7627
    @mizo7627 4 ปีที่แล้ว

    Thanks for the video !

  • @dilbar12345
    @dilbar12345 4 หลายเดือนก่อน

    thanks mannn....still helpful in 2024

  • @kharillo6882
    @kharillo6882 3 ปีที่แล้ว +3

    Is there a way to intercept and modify the request being sent. For example if im typing a message on instagram to someone, can i intercept the message and change it

    • @N0SC0P3D
      @N0SC0P3D 3 ปีที่แล้ว

      did you ever figure it out bro?

    • @blockify
      @blockify 3 ปีที่แล้ว

      if you figure it out let us know, i wanna troll my friends

    • @N0SC0P3D
      @N0SC0P3D 3 ปีที่แล้ว

      @@blockify
      did you figure it out man?

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว

      I've not tried it, but you could well be able to do that. However, I'm guessing sites such as Instagram would be properly validating and filtering any external user input.

  • @novianindy887
    @novianindy887 2 ปีที่แล้ว +1

    how to make it automatic changing string/text on the fly?

  • @studyrelaxwithme4564
    @studyrelaxwithme4564 8 หลายเดือนก่อน

    The changes that you apply on the body Will affect only your client PC (then It Is only a visual modify) or Will send the response to the server? Thanks

  • @hellopropop
    @hellopropop 4 ปีที่แล้ว

    THANK you very much INTELLIGENT BOIIII !

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      You're welcome. I'm glad the video helped.

  • @kannadhanunjaya3627
    @kannadhanunjaya3627 3 ปีที่แล้ว

    Good video bro.
    Make more videos on burp suit.

    • @WebDevwithMatt
      @WebDevwithMatt  3 ปีที่แล้ว

      Trying to put time aside to do that. Thanks for the support.

  • @joe-jb3lz
    @joe-jb3lz 2 ปีที่แล้ว

    at 3:35 is where i can’t figure out

  • @MHatip-qy5yl
    @MHatip-qy5yl ปีที่แล้ว

    This is for the life this is for

  • @muhammedanswarc.k4646
    @muhammedanswarc.k4646 3 ปีที่แล้ว

    Good job bro

  • @شنقريحة
    @شنقريحة 9 หลายเดือนก่อน

    Not working , if u turn off the intercept after that and refresh the page its will became the first one so changes are virtual

  • @OthmanAlikhan
    @OthmanAlikhan 4 ปีที่แล้ว

    Thanks for the video and awesome voice =)

  • @sierraegerton2789
    @sierraegerton2789 3 ปีที่แล้ว

    thanks for the video, how do you get the community edition????? need to send an backdated email Help!!!!

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว

      I just downloaded it. The PortSwigger website's changed since I last check it out. It seems that you now have to submit your email address to download that version.

  • @ClaudioSantos-jb6ir
    @ClaudioSantos-jb6ir 3 ปีที่แล้ว

    can i edit the request too? to get the server answer that i want.

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว +1

      As you compose the request yourself, you sure can.

  • @nafeesaa9289
    @nafeesaa9289 3 ปีที่แล้ว

    hi, i have a doubt! pls let me know... if i intercept a request, edit its response, inject an alert script , if that script is reflected in the website is that an xss vulnerability??

    • @faithdouglas589
      @faithdouglas589 2 ปีที่แล้ว

      Same question for me. I need to know the answer as well. Please

  • @when542
    @when542 4 ปีที่แล้ว

    Where is the next repeater video about burp

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      In development, actually. Thanks for the encouragement.

  • @mitpifa
    @mitpifa 5 ปีที่แล้ว

    How can you modify part of the new request with a VARIABLE, which was got from the previous request response? Thanks.

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      Honesly, that I don't know. I'll see what I can find out for you, though.

  • @sanketyadav328
    @sanketyadav328 4 ปีที่แล้ว

    What's the name of this attack?

  • @dongibson8639
    @dongibson8639 4 ปีที่แล้ว

    Can I buy something off of a site using this?

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      Possibly. It depends on the quality of the site's code.

  • @braddavid6897
    @braddavid6897 5 ปีที่แล้ว

    Seems pretty cool. But need to see the actual request from step one like enter in url and stuff. This is pretty cool but need it fully detailed like in steps.

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      Might be best if I re-shoot the video to include that.

  • @Mannnmauji
    @Mannnmauji 4 ปีที่แล้ว

    upload full playlist please

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      I have to go and make the videos. Do you want a full series?

    • @Mannnmauji
      @Mannnmauji 4 ปีที่แล้ว

      @@WebDevwithMatt yes please... The way you explain is amazing.

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      @@Mannnmauji you are too kind. Thank you. I'm currently working through planning a course on Burp Suite. No timeline yet for when it will start rolling out.

  • @maringrkovic2122
    @maringrkovic2122 4 ปีที่แล้ว +1

    Eyo everyone watching,my burpsuite wasn't intercepting and I got NO help from any videos on yt and it was fuckin me over, all I tried failed, but then I found out that burpsuite wasn't intercepting my requests bcz I was trying to crack the DVWA (damn vulnerable websitr application) and that is on your localhost so you have to enable hijacking localhost (just type it in yt), just puttin it out there so you don't have the same issue as I did :)

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      Glad you were able to solve your issue.

  • @roelgambong2224
    @roelgambong2224 4 ปีที่แล้ว

    Can you perform main the middle attack by intercepting OTP request from an email account’s phone number attached to it?

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว +2

      Honestly, that I'm not sure of. I'll investigate and see what I find. Thanks for asking.

    • @roelgambong2224
      @roelgambong2224 4 ปีที่แล้ว

      Software Development with Matt wow never expected you would replied to my message. I found a very informative video th-cam.com/video/3XUo7UBn28o/w-d-xo.html it shows there at somewhere 31 mins how it was performed using wireshark, but can’t fully understand how it was done in a step-by-step manner. I would be so much thankful if you can study that video and make a video on how it’s done.

    • @ifyanaka9160
      @ifyanaka9160 4 ปีที่แล้ว

      @@WebDevwithMatt hey let's talk on telegram @Savagelone, my chrome doesn't work with burp suite

  • @alexsorrow6133
    @alexsorrow6133 4 ปีที่แล้ว

    But when you upload your browser Edgar Wrong is disappear and switch on right name

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      Sorry, I don't follow what you're saying?

  • @rektbish5315
    @rektbish5315 3 ปีที่แล้ว

    How can I do this with an android application more like a game

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว

      I'm not sure, as I'm not a big Android user.

  • @adamthepanda00
    @adamthepanda00 4 ปีที่แล้ว

    Does this work with other websites online? and if so how do I need to configure the proxy? Thanks, I loved the vid.

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว

      It will work with whatever website you want to interact with. What way do you need to configure the proxy, or what is the website that you want to interact with? And thanks for the feedback on the video. It really means a lot.

    • @adamthepanda00
      @adamthepanda00 4 ปีที่แล้ว

      @@WebDevwithMatt thanks for the response, it was quite quick, but I realised that proxying wasn't how I needed to approach my issue. Thanks for the help anyway. Sorry for the inconvenience.

  • @matthough4124
    @matthough4124 6 ปีที่แล้ว

    I can't find anything that I've missed but I've tried multiple times from scratch and the request never gets intercepted. Any ideas?
    Ps. Yes I checked that intercept was turned on...

    • @matthough4124
      @matthough4124 6 ปีที่แล้ว +1

      EDIT: You didn't mention in the video that you need to configure the listener proxy.

    • @WebDevwithMatt
      @WebDevwithMatt  6 ปีที่แล้ว

      Hi @@matthough4124, thanks for getting in touch about this. A small configuration of the proxy is covered from about 1:41 onwards. Is that what you're looking for, or have I misunderstood you?

    • @vegan.
      @vegan. 6 ปีที่แล้ว +1

      @@WebDevwithMatt Yeah but you don't mention at all configuring the browser to use burp as it's proxy

    • @matthough4124
      @matthough4124 6 ปีที่แล้ว

      @@WebDevwithMatt its ok i worked it out, on windows the browser and the network settings need to be configured to use the proxy that the burp suite makes

    • @daviddaedae
      @daviddaedae 6 ปีที่แล้ว

      @@matthough4124 Anyway you can share how you configured this?

  • @kiefferballesteros9791
    @kiefferballesteros9791 6 ปีที่แล้ว

    Could you use other methods in the condition like PROPFIND?

    • @WebDevwithMatt
      @WebDevwithMatt  6 ปีที่แล้ว

      Sure should be able to. I'll have a look and get back to you.

  • @stellabckw2033
    @stellabckw2033 4 ปีที่แล้ว

    would be cool if you could do it in an automated way, for example: if that line matches with a cartain regex, change it to xyz. or smth like that

    • @WebDevwithMatt
      @WebDevwithMatt  4 ปีที่แล้ว +1

      At this stage, I don't know if that's possible, but I strongly suspect that it is. I'll see what I can find out.

    • @stellabckw2033
      @stellabckw2033 4 ปีที่แล้ว

      @@WebDevwithMatt subscribed :3

    • @K4njiz
      @K4njiz ปีที่แล้ว

      ever found out anything ?@@WebDevwithMatt

  • @abdulkareem8227
    @abdulkareem8227 3 ปีที่แล้ว

    Bro,
    How do I change number in 1xbet using Burp Suite

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว

      Not sure, sorry. I don't know that site.

  • @udupi123456
    @udupi123456 5 ปีที่แล้ว

    Your voice and this video both are very interesting... I m from India.. you video is what I wanted.

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      Thanks kindly. I really appreciate the feedback.

  • @heijiju
    @heijiju 4 ปีที่แล้ว

    Aussies are the best. No doubt. 👏

  • @梁兵-t5n
    @梁兵-t5n 4 ปีที่แล้ว

    thank u

  • @jegadeeshvk9927
    @jegadeeshvk9927 3 ปีที่แล้ว

    Solution for this vulnerability??

    • @MsSoldadoRaso
      @MsSoldadoRaso 3 ปีที่แล้ว

      use front end and backend

  • @SanskarSaini-sl6dc
    @SanskarSaini-sl6dc 4 หลายเดือนก่อน

    How to get burpsuite

  • @turtleman1259
    @turtleman1259 3 ปีที่แล้ว

    If you could help my do this step by step today that would be awesome

    • @WebDevwithMatt
      @WebDevwithMatt  2 ปีที่แล้ว

      When you say "step by step", do you want a hard list in the comments?

  • @travaa54
    @travaa54 5 ปีที่แล้ว

    I think this works only when you load the website from your computer

    • @MatthewSetter
      @MatthewSetter 5 ปีที่แล้ว

      Why's that Jakov? If the request can be intercepted, the response can be modified. Do you have a particular scenario as an example?

    • @travaa54
      @travaa54 5 ปีที่แล้ว

      @@MatthewSetter i have done this on my website and i changed the title..but it works only from my laptop, when i open website from my phone or another pc there is no change.

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      Ah, that explains it. I'm guessing that for your phone or PC you haven't changed the proxy to be the one in Burp Suite. If that's the case then Burp Suite cannot intercept those requests.

    • @travaa54
      @travaa54 5 ปีที่แล้ว

      @@WebDevwithMatt Hi..Im using foxyproxy addon for google chrome to setup proxy, port iy 8080 and ip is 127.0.0.1...when i made changes to html in burp, changes are made in website when i look from the device that im using burp..im using burp for windows, but when i enter my website from my phone nothing changes, all text is the same..can you please help me?

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      It seems like your phone's not configured to use the same proxy.

  • @bigdatax6512
    @bigdatax6512 5 ปีที่แล้ว

    why you sound like my dad when he teach me something....but hey..thats cool ...it works for me

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      Maybe it's just my voice :-) along with the proximity effect of the mic, which I LOVE!

  • @SNEHAM-w3b
    @SNEHAM-w3b 4 ปีที่แล้ว

    Hi sir, it is really great
    Can you please do more vedios on burp suite
    Thanks,
    Pavan Kumar

  • @chefsputnik1
    @chefsputnik1 6 ปีที่แล้ว +5

    You didnt modify any request parameter. Modifying the response is useless.

    • @clickscolourblackramiz92
      @clickscolourblackramiz92 6 ปีที่แล้ว +1

      Hey

    • @WebDevwithMatt
      @WebDevwithMatt  5 ปีที่แล้ว

      @@clickscolourblackramiz92 it's helpful for a couple of reasons, such as getting a feel for the application, and giving a client a different response to see how it handles it.

  • @holahola6860
    @holahola6860 4 ปีที่แล้ว

    Can others see that

  • @maharajraj2909
    @maharajraj2909 ปีที่แล้ว

    Bro help me please

  • @musicdhwani634
    @musicdhwani634 3 ปีที่แล้ว

    niceee

  • @wickedsnuk3812
    @wickedsnuk3812 6 ปีที่แล้ว +1

    U said U will explain about other stuffs and you didn't :D

    • @WebDevwithMatt
      @WebDevwithMatt  6 ปีที่แล้ว

      I didn't? Sorry about that. I'll have to update the video to either not mention that, or to add those other things that I mentioned. Thanks for calling me out on that.

    • @_productivity__nill_1131
      @_productivity__nill_1131 5 ปีที่แล้ว

      @@WebDevwithMatt very funny, the video still hasn't been uploaded

  • @abdirahmanabdirizak787
    @abdirahmanabdirizak787 4 ปีที่แล้ว

    😂😂 is just like changing in ispect element

    • @CarlosHenrique7
      @CarlosHenrique7 4 ปีที่แล้ว

      😂😂 oh, not always. There are some cases that we need to test right after receiving the response

    • @aztsetodkivok408
      @aztsetodkivok408 3 ปีที่แล้ว

      Except the big difference is this makes changes in the server and inspect element only does it in your browser

    • @manhu8900
      @manhu8900 3 ปีที่แล้ว

      @@aztsetodkivok408 but when page resfreshed, it's back to original value.

  • @Hackedpw
    @Hackedpw 4 ปีที่แล้ว

    k