Burp Suite User Forum

Create new post

"Lab: Basic SSRF against another back-end system" does not work

"Lab: Basic SSRF against another back-end system" does not work The lab redirects to an error site FYI

Last updated: Nov 14, 2019 11:18AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

100% CPU utilization in Burp Suite Pro 2.1.03

Burp Suite Pro 2.1.03 keeps causing 100% CPU utilization when running an audit scan (earlier known as scanner). The scan task works for approximitely 2500-3000 requests after which it stops. Stopping the scanner does not...

Last updated: Nov 13, 2019 02:59PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

False positives

I am getting too many false positives of "Content type incorrectly stated" vulnerability all the time. My last occurence is: '''The response states that the content type is font/x-woff. However, it actually appears to...

Last updated: Nov 13, 2019 02:54PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Scanner status indication is pretty unreliable.

1) The scanner very often shows that a scan is completed by showing full bar and by text also, while the number of requests is increasing and actually the scan isn't completed. 2) The scanner very often shows that a scan...

Last updated: Nov 13, 2019 02:52PM UTC | 3 Agent replies | 1 Community replies | Bug Reports

If you crawl, the status code of the site map Response will change

If you crawl, the Response status code displayed on the site map is changed from "301" (redirect) to "200" (no redirect). When Crawl is executed, the contents of Response will be the contents after redirect. Originally,...

Last updated: Nov 13, 2019 11:41AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

some content characters change when request is sent to intruder

hi, I attached a docx file with simple content (like some lines) in it, then sent the request to intruder and one to repeater from intercept (proxy) part for further investigating of request, it seems some character in the...

Last updated: Nov 11, 2019 10:49AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Re: Burp can't send any requests

Burp Suite constantly gives me issues but today is probably the worst. It won't send any requests to any site period. Proxy intercept is off and I have tried sending simple GET requests to google.com using repeater which...

Last updated: Nov 07, 2019 10:53AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

NET::ERR_CERT_WEAK_KEY

Hello, I've just updated my macOS to Catalina and Burp to version Version 2.1.05. The problem is that Chrome does not want to initiate a connection with Burp Proxy and shows the error "Your connection is insecure" with...

Last updated: Nov 05, 2019 09:08PM UTC | 0 Agent replies | 1 Community replies | Bug Reports

Burp does not load url from environment variable in windows

Hi Team, I have configured the burp enterprise edition with "jenkins" and i have created a "execute windows batch script" to load the target url for scanning. Also, i have confgirued the burp scan plugin with below...

Last updated: Nov 05, 2019 11:21AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

header injection using burp intruder is not working as expected

Hi, I noticed one problem while trying to do automatic header injection using intruder. i created emty placemarker in positions tab because I want to incert new header from the list of headers I have That is not a...

Last updated: Nov 04, 2019 02:12PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp not loading on a specific site

What do I do if Burp is causing my browser not to load a specific site. All of the proxy settings are configured correctly, I am able to browse to other sites and I can see the req/responses. But for this specific site,...

Last updated: Oct 30, 2019 01:49PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Separation of query string

Hi, When I access a URL like following Burp recognizes one parameter its name="JSESSIONID", value="foo?bar=baz". http://localhost/;JSESSIONID=foo?bar=baz Screenshots: http://imgur.com/OY9NkvU (Raw...

Last updated: Oct 24, 2019 11:44AM UTC | 4 Agent replies | 4 Community replies | Bug Reports

Updated burp community edition broke burp

I updated burpsuite community edition and now every connection generates "Host is down (connection failed)" and "java.net.socketexception: host is down (connect failed)" errors. I am using Firefox 69.0.3 (64-bit) and...

Last updated: Oct 24, 2019 10:40AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Jenkins Jobs ran not coming in Burp Enterprise Scan dashboard

Hello Team, We have integrated Burp Enterprise with CloudBees Enterprise Jenkins using plugin: Burp Scan. The Jenkins job ran successfully using API. However the Jenkins job details are not displayed on the Burp...

Last updated: Oct 24, 2019 08:42AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Cert validity too long

Hi, The error described in the following link still happens with the latest version of Burp (1.7.07), despite being resolved as fixed in the September 8 release...

Last updated: Oct 23, 2019 03:56PM UTC | 2 Agent replies | 7 Community replies | Bug Reports

right click not working for V 2.1.04 in MacOS catalina

Hello, Within intruder, when using Catalina MacOS, right click on the window within burpsuite v2.1.04 latest, it does not allow send to repeater or drop down selection of options where to route the selection to. Please...

Last updated: Oct 23, 2019 12:49PM UTC | 2 Agent replies | 3 Community replies | Bug Reports

Errors: unable to relocate function

I am using Burp Pro 2.0.13 on a Kali VM up to date as a week ago at least. It's been working fine with a normal manual crawl and send to scanner style workflow. Recently I just tried to run a new scan on a site using the...

Last updated: Oct 22, 2019 09:45AM UTC | 10 Agent replies | 10 Community replies | Bug Reports

GetParameters (IRequestInfo) bug

Hi, I am using the "getParameters()" method of IRequestInfo and I have found a bug. When a request is parsed by this method it returns all the parameters that it found in "get parameters", "post parameters" and cookies....

Last updated: Oct 22, 2019 03:26AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Unable to resume Crawl and Audit Scan after consecutive audit items failing

Hello, Anytime that I try to run the Crawl and Audit Scan, I run into consecutive audit items failing due to 'Errors: unable to relocate function'. I am then unable to resume the scan/auditing (when I click the play...

Last updated: Oct 21, 2019 04:06PM UTC | 4 Agent replies | 4 Community replies | Bug Reports

hola

<script>alert(1)</script>

Last updated: Oct 18, 2019 02:55AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Page 110 of 142

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image