Burp Suite — Web Security Education

Learn Burp Suite Safely

Guided web security tutorials from aspect, built for beginners, IT teams, developers, and small businesses that want to understand how web application testing works.

aspect is proud to be a Burp Suite Champion, helping make web security education more accessible through practical, safe, and responsible tutorials.
Responsible Use Notice

These tutorials are for educational and authorized security testing only. Do not scan, attack, fuzz, exploit, or attempt to access systems without explicit permission. All Aspect tutorials teach safe workflows using authorized targets and intentionally vulnerable labs.

Learning Tracks

Choose a track based on your background and goals. All tracks use authorized targets and safe, legal practice environments.

Track 1
Beginner Track

Start with the basics: what Burp Suite does, how to use Burp's browser, and how to intercept your first HTTP request.

  • What is Burp Suite?
  • Installing Burp Suite Community
  • Using Burp's browser
  • Intercepting your first request
  • Understanding HTTP requests and responses
Track 2
Web Testing Track

Learn practical testing workflows for common web application security concepts using authorized training environments.

  • Using Repeater
  • Testing login forms
  • Understanding cookies and sessions
  • Finding IDOR-style issues
  • Testing reflected input
  • Basic file upload testing
Track 3
Professional Workflow

Learn how to turn testing activity into clean, useful, client-ready findings that communicate risk clearly.

  • Taking clean screenshots
  • Documenting reproduction steps
  • Writing severity and impact
  • Explaining remediation
  • Building a web security finding
Track 4
SMB Security Track

Understand how web security issues become real business risk for small and medium-sized businesses.

  • Why website forms get attacked
  • Why login portals need testing
  • How web vulnerabilities affect SMBs
  • How testing supports risk reduction

Tutorial Library

Individual video tutorials. Each lesson covers one concept using safe, authorized practice targets and is designed to be completed in under 20 minutes.

Beginner ⏱ 10 min
Intercepting Your First Request

Learn how Burp sits between your browser and a web application so you can inspect HTTP requests and responses.

ProxyHTTPBurp Browser
Beginner ⏱ 12 min
Using Repeater

Learn how to resend, modify, and compare HTTP requests while testing safely on authorized targets.

RepeaterRequestsManual Testing
Beginner ⏱ 15 min
Understanding Cookies and Sessions

Learn what session cookies are, why they matter for web security, and how Burp helps inspect them.

CookiesSessionsAuthentication
Beginner ⏱ 15 min
IDOR Basics

Learn how insecure direct object reference issues happen using safe, authorized examples in training labs.

Access ControlAuthorizationIDOR
Beginner ⏱ 15 min
Reflected Input and XSS Basics

Learn how reflected input works and why output encoding matters. Demonstrated in intentionally vulnerable labs only.

XSSInput ValidationOutput Encoding
Beginner ⏱ 10 min
Writing a Clean Web Finding

Learn how to document evidence, impact, reproduction steps, and remediation in a format that communicates real risk.

ReportingEvidenceRemediation

Practice Safely

Only test systems you own, have explicit permission to test, or intentionally vulnerable training labs. The resources below are designed for safe, legal practice.

Free
PortSwigger Web Security Academy

Free web security learning materials and interactive labs from PortSwigger, the makers of Burp Suite. The gold standard for web security practice.

Open Source
OWASP Juice Shop

An intentionally vulnerable web application for safe security training. Run it locally to practice Burp Suite workflows without legal risk.

Open Source
OWASP WebGoat

A deliberately insecure training application from OWASP for learning common web vulnerabilities in a safe, controlled environment.

From Finding Bugs to Communicating Risk

Finding a vulnerability is only part of security testing. A useful finding explains what happened, why it matters, how to reproduce it, and how to fix it. Clear documentation is what makes a test result actionable for the people who need to respond.

A complete finding includes

  • What the vulnerability is and where it exists
  • Steps to reproduce the behavior
  • Evidence: screenshots, request/response pairs
  • Impact on the business or end user
  • Severity rating with CVSS justification
  • Specific remediation guidance
Built by Aspect

XPLT — Bug Bounty & Pentest Documentation

Once you find something worth reporting, you need a place to write it up properly. XPLT is a report writing tool built for bug bounty hunters, pentesters, and security researchers who want clean, structured documentation without the friction.

PDF & Export Output

Generate professional, client-ready reports from your findings. Export clean PDFs ready to submit to programs or share with stakeholders.

Evidence Attachment

Attach screenshots and request/response pairs directly to findings. Keep your evidence organized and tied to the right vulnerability.

Bug Bounty & Pentest Modes

Handles both bug bounty writeups and full pentest engagements. Integrates with BBP platforms, CTF systems, and Burp Suite Community & Pro.

Try XPLT → Available on iOS & Android  ·  macOS & Linux coming soon

Need Help Testing Your Web Applications?

Aspect helps small and medium-sized businesses understand and reduce web application risk through practical cybersecurity services, testing, reporting, and remediation guidance.

Talk to Aspect
Coming Later

Hosted Training Sandbox

Aspect plans to expand this hub with a dedicated hosted lab environment at lab.aspect2020.com. For now, this learning hub focuses on videos, written walkthroughs, and safe external practice resources. The sandbox phase will be announced when it is ready.