The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Audit Phase gets shows finished but gets skipped

Hi Team, When I try to do the following mentioned scan, it completes the authenticated crawl as it should but the audit phase gets skipped the next moment. It shows as finished but it doesn't run even for a second. There...

Last updated: Aug 02, 2024 01:40PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Issue in an Academy Lab

Hello it would seem that there is an issue with the Lab for: "Exploiting server-side parameter pollution in a REST URL". After the request for the passwordResetToken is submitted the response does not have a valid password...

Last updated: Aug 02, 2024 10:55AM UTC | 4 Agent replies | 4 Community replies | Bug Reports

No more activations allowed for this license

I get this for when I try to move my Burp installation to a new computer at work. Can you please add some more for me. This message is really weird, as you're licensing terms seems to be "yeah, it's a per user license, and...

Last updated: Aug 02, 2024 09:01AM UTC | 18 Agent replies | 19 Community replies | Bug Reports

Can't send request to get trial of burpsuite pro

I am trying to send request to test pro version of burpsuite, but my email address does't fit. Can you help me ?

Last updated: Aug 02, 2024 08:42AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp's headless browser not launching

Hi guys, I am looking for assistance with an issue I have encountered in Burp. I have been using Burp Professional in my M1 Macbook and always worked without an issue. Now all of a sudden, the headless browser does not...

Last updated: Aug 02, 2024 08:29AM UTC | 1 Agent replies | 2 Community replies | Bug Reports

I am getting the below Java Stackoverflow error when running the latest Burp Proxy jar file with OpwnJDK 20.0.1 and 20.0.2, with or without extensions

C:\Software\Sectools\Appsec>c:\openjdk-22.0.2\bin\java -Xmx24576M -jar burpsuite_pro_v2024.6.3.jar java.lang.StackOverflowError at java.desktop/javax.swing.text.View.getViewFactory(View.java:1028) at...

Last updated: Aug 02, 2024 08:21AM UTC | 5 Agent replies | 6 Community replies | Bug Reports

Burp Academy: Lab: Authentication bypass via encryption oracle, Missing Error Messages

Im trying to complete the lab: "Authentication bypass via encryption oracle" without success. I followed the regular solution, as well the community based video, but it seems, that i dont receive any error messages, when i...

Last updated: Aug 01, 2024 01:59PM UTC | 5 Agent replies | 6 Community replies | Bug Reports

Lab does not reset after a long time

Hi, I tried to solve the "Lab: Basic clickjacking with CSRF token protection" but accidentally deleted my user. I have waited for an hour many times but the lab hasn't reseted yet. May anyone help?

Last updated: Aug 01, 2024 07:20AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Lab: CSRF where token is tied to non-session cookie

those are also incorrectly processed by my lab, my payload in search does not read properly. Everything is fine in response, but the next request does not execute. request: GET...

Last updated: Aug 01, 2024 07:16AM UTC | 6 Agent replies | 8 Community replies | Bug Reports

Web cache poisoning via ambiguous requests

Currently the lab can't be completed since _lab and session cookies have the Httponly flag when the lab is first loaded. The alert(document.cookie) will never fire correctly.

Last updated: Jul 31, 2024 01:05PM UTC | 3 Agent replies | 5 Community replies | Bug Reports

SameSite Strict bypass via sibling domain LAB seems to be broken

The exploit server log seems to fail at grabbing the requests from the victim after exploit delivery. It seems that the victim never actually clicks on the exploit? As I see nothing in the log or any DNS interaction on...

Last updated: Jul 31, 2024 12:32PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burpsuite slow interception

Hello there, I'm testing an Android app and I have burp suite pro and requests and responses are too slow when I make it as the proxy and server not responding I tried the free burp and its working fine I tried many...

Last updated: Jul 29, 2024 09:20AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab 'CSRF where token validation depends on token being present' not solve after email change

Viewing the exploit URL is able to change the email successfully, when I click deliver exploit to vicitm, the exploit not working and unabel to solve the lab. Please check it from your end if there is a bug.

Last updated: Jul 29, 2024 07:51AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

There's something wrong with lab "Targeted web cache poisoning using an unknown header"

Hello, Multiple times I've tried to complete this but it breaks. Sometimes when I try to open this lab, I get a 504 error saying no response. When I do get in, when I get to the step to add "X-Host: example.com", when I...

Last updated: Jul 28, 2024 03:28PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: OAuth account hijacking via redirect_uri: SessionNotFound

Hi, In the lab titled "Lab: OAuth account hijacking via redirect_uri", I am unable to view the exploit when using the iframe payload on the exploit server. Instead, I get the error below inside the...

Last updated: Jul 28, 2024 12:06PM UTC | 2 Agent replies | 6 Community replies | Bug Reports

Stealing OAuth access tokens via a proxy page

I am trying to solve the exercise "Stealing OAuth access tokens via a proxy page". When I embed the iframe on the exploit server like this: <iframe...

Last updated: Jul 28, 2024 12:04PM UTC | 0 Agent replies | 2 Community replies | Bug Reports

Burp browser is crashing

Hi Team, I am using burp professional version 2024.5.5 and the browser is continuously crashing. Could you please help me here. Thanks

Last updated: Jul 26, 2024 07:15AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

solved labs status not updated

hello , I have been using your website in the last few months and i haven't encountered a similar problem until the past couple of weeks .When I solve a lab , it takes a long period of time to update the status to "lab...

Last updated: Jul 26, 2024 06:56AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Labs: Web cache poisoning not solved

I can successfully exploit myself but non of the labs get marked as solved. I've tried the first three web cache poisoning labs.

Last updated: Jul 25, 2024 08:02AM UTC | 6 Agent replies | 9 Community replies | Bug Reports

Lab: Exploiting cross-site scripting to capture passwords problems

Hi, The provided solution will trigger DNS requests that my collaborator sees. However, the lab will not trigger the HTTP request. I have confirmed that the collaborator will see http requests when I test the collaborator...

Last updated: Jul 25, 2024 07:37AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Page 11 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image