The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scanner does not work through upstream proxy

In Burp 2020.9 and 2020.9.1, Scanner times out when going through an upstream proxy with NTLM auth. 2020.2 is not having this issue.

Last updated: Sep 15, 2020 08:39AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Blind SQL injection with conditional responses - on WebSecurity Academy

The page on this lab always showing "Welcome back!" whether there is correct SQLi query or not even without using SQLi on the TrackingId cookies. It's hard to find the answer for this lab. Thank you. Best...

Last updated: Sep 15, 2020 02:40AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Unicode Normalization Bug

During one of the pentests I was attempting to test for the Hostsplit unicode normalization vulnerability by tampering with the host header. More details about this vulnerability can be found...

Last updated: Sep 14, 2020 02:11PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Lab: Reflected XSS into HTML context with all tags blocked except custom ones lab is not working

hey i have been doing some labs but i got to notice that the above content lab is passing the payload even i get a xss pop up but still says lab not solved i have done refreshing the page and also i have tried it on the...

Last updated: Sep 14, 2020 12:55PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burpsuite does accept external connections on Mac OSX Catalina

I have burp running on the mac osx catalina and listening on all interfaces. in the mac osx firewall the burpsuite and java are allowed to accept incomming connections but the burp suite doesnt receive any traffic from the...

Last updated: Sep 11, 2020 06:39AM UTC | 3 Agent replies | 4 Community replies | Bug Reports

Burp Profession V2020.9.1 is eating CPU and Memory

My burp profession v2020.9.1 is consuming cpu and memory usage and it is just opening. It is eating 5GB of my laptop memory constantly.

Last updated: Sep 10, 2020 01:46PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp licence activation failed on reinstalled windows workstations after upgraded

Could you please help to reactivate the two burp licenses under my account. Since after windows upgraded, our burp licenses have been lost and need to reactivate however all the burp licenses cannot be used when I try...

Last updated: Sep 09, 2020 07:14AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Receiving error on accessing websites via Burpsuite Community 2020.9

I'm getting the following errors when attempting to use Burp to analyse web traffic.I am using embedded browser to access websites. 1599157875112 Error Proxy [54] The client failed to negotiate a TLS connection to...

Last updated: Sep 04, 2020 01:10PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Facing Issues while Site scanning

I have Burp suite enterprise edition installed. I am Getting "Waiting for agent" error while any site scanning If I go to agents section I can see below error "An unexpected error occurred. If this problem persists,...

Last updated: Sep 04, 2020 10:19AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Critical Service Issue : External Service Interaction(DNS)

When we run Burp Scan to Our Xactly product, we are seeing a Critical issue related to "External Service Interaction(DNS)" is shown in scan reports. We tried to fix the issue in multiple ways and didn't help. I have the...

Last updated: Sep 02, 2020 12:59PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Active Scanning Using Default Collaborator Server Spoofing Instead of Private Collaborator Server

Under Project Options, I have "Use a private Collaborator server" selected with the name of an external Ubuntu 16.04LTS host that has Burp Collaborator Server running on it. However, when I dig through the results from...

Last updated: Sep 02, 2020 12:44PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Lab - Exploiting XSS to perform CSRF

Hello! I'm trying out this lab and, after submitting the payload to the comment section, the lab does not solve at all. I have confirmed that the payload works by accessing myself the forum and i see that the...

Last updated: Sep 02, 2020 12:44PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Audit Item Status shows " Error Request time out and Unknown Errors "

Hi, While using the Active scan & Crawl Audit scan against my Webserver. Scan is not able to completed it. * I could see " skipping Current Insertion point due to many consecutive un known errors. * For few...

Last updated: Sep 02, 2020 12:29PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Intruder marks are shifted

Dear PS team, I'm using Burp on MacBook Pro via Fusion VM - standard version with no strange configuration. I've found annoying Burp behaviour when im in Intruder - every positions marks made by Burp or by me are shifted...

Last updated: Sep 02, 2020 10:49AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

BurpSuite => Mobile App TLS Connection Problem

Hello, I have been getting a TLS connection error in the BurpSuite recently. I'm installing the "http://burp" Burp Certificate on mobile device. The certificate is running in the web browser. SSL OK. But, doesn't work...

Last updated: Sep 02, 2020 08:49AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

SSL Handshake Error

With Burp, I am trying to view the following website - https://self-repair.mozilla.org/ but I am not able to proxy it via Firefox. The error received (in alerts) is - javax.net.ssl.SSLException: Received fatal alert:...

Last updated: Sep 01, 2020 03:57PM UTC | 3 Agent replies | 11 Community replies | Bug Reports

cross site script

I have scanned the application using Burp suite professional licensed version, where I have received the cross-site scripting please refer to the below issues description. The original request used a Content-type...

Last updated: Sep 01, 2020 11:09AM UTC | 3 Agent replies | 3 Community replies | Bug Reports

gzip in request

Im assessting a mobile application that sends HTTP requests compressed. I have activated the check "proxy>options>miscelaneous>unpack gzip/deflate requests". But, when the request is unpacked, the request has still the...

Last updated: Sep 01, 2020 09:59AM UTC | 2 Agent replies | 0 Community replies | Bug Reports

Unable to find Burpsuite JAR file

I have downloaded the brupsuite pro edition and i see it is a .sh file. I am trying to follow the procedure mentioned but i am unable to find the .JAR file which is being mentioned in the steps. I am running the latest...

Last updated: Sep 01, 2020 07:56AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Can't install / launch burpsuite pro on latest Kali

Hi. I am trying to install burpsuite pro 2020.8 on the latest Kali release. I've tried using openjdk-11 as well as openjdk-8 with both results. after running burpsuite_pro_linux_v2020_8.sh I can see a new window hoping which...

Last updated: Aug 30, 2020 05:16PM UTC | 4 Agent replies | 4 Community replies | Bug Reports

Page 105 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image