Choose the genuinely free edition
Burp Community Edition provides manual web-testing tools. The automated scanner and some reporting features belong to paid editions and are not part of this workflow. PortSwigger Web Security Academy offers learning labs; use a lab assigned to you rather than a live third-party site.
Start a contained session
- Install Community Edition from the official download page.
- Choose a temporary project and the default configuration for a first exercise.
- Open Burp's built-in browser from Proxy. This avoids changing your ordinary browser's system trust configuration for the beginner exercise.
- Open only your assigned Academy lab and set the target scope to that lab.
Do not sign into your personal email or banking accounts in a browser whose traffic you are intercepting for practice.
Inspect a request
With interception off, browse a harmless lab page and review Proxy HTTP history. Select the request and read its method, host, path and response status. If you turn interception on, use Forward for the request you intend to send and turn interception off when finished.
A page hanging while interception is enabled can simply mean Burp is holding its request. That is different from a broken network connection.
Repeat a read-only lab request
Send a lab GET request to Repeater. Send it again unchanged and compare the response. Then, within the lab's instructions, change a harmless value such as a search term and inspect the difference. Repeating a state-changing POST can duplicate an action, so do not experiment with real orders or account changes.
Verify the lesson
Explain the distinction between a request, response, proxy history and a Repeater tab. Confirm the host remains your assigned lab. You should be able to show which field changed and what effect it had without relying on an automated vulnerability score.
Common mistakes
Community Edition is not an unrestricted Pro trial. A scope setting helps organise testing but does not confer permission. Exported requests can contain cookies, tokens or lab credentials; keep them private and redact before sharing.
Clean up
Close the lab browser and temporary session. If you configured an external browser or installed a CA certificate in a separate exercise, undo that setup following the official instructions. Keep ordinary browsing separate from the learning proxy.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.