Burp Suite User Forum

Create new post

Excluded scanner issue still showing up in report

Using 1.7.30 Minor thing here... I excluded a bunch of individual scan issues and ran a scan. In the final results, I still had "Python code injection" showing up in the results of issue types, even though it was excluded.

Last updated: Jan 10, 2018 08:48AM UTC | 3 Agent replies | 4 Community replies | Bug Reports

Intruder not starting a saved attack

Hi All I have been running an intruder attack and saving periodically and restarting without issues. However following a necessary save, reboot and resume i have been unable to get intruder to successfully open the saved...

Last updated: Jan 05, 2018 03:39PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Issue type vs Issue name uniqueness in scanner XML output

Hi team, I'm working on the Burp parser for Dradis (http://dradisframework.org) and one of our users has reported an issue with the way two different findings are reported under the same Issue type number. It seems...

Last updated: Dec 27, 2017 04:34PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp Suite generates "weak ephemeral Diffie-Hellman key" error with Firefox Developer Edition

I've been using Burp Suite with Firefox Developer Edition, but as of today, I cannot make HTTPS connections when using Burp Suite as a proxy. I now get the following error message: An error occurred during a connection to...

Last updated: Dec 19, 2017 10:16AM UTC | 4 Agent replies | 11 Community replies | Bug Reports

Burp Intruder Missing Delimiter

Hi, I have seen an unexpected behaviour in Burp when using Intruder and fuzz points. Within the Intruder you can define fuzz points via the § character, however, you don't have to use two of them. If only one § is used,...

Last updated: Dec 19, 2017 08:48AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Bug in Scanner Issue Activity

In my current project the greatest ID is 2634. At some point burp decided to continue the counting from around 1000 and I don't know whether it overwrites my existing vulnerabilities. This behavior has been noticed only on...

Last updated: Dec 13, 2017 12:03PM UTC | 4 Agent replies | 3 Community replies | Bug Reports

Burp API - IContextMenuInvocation - Modified request/response access/hinting

In the Burp extender API when retrieving the selected messages from the proxy history, I don't see any way to know if the selection occurs into a modified response/request panel or the original one....

Last updated: Dec 12, 2017 04:35PM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Encounter blank screen when installing burpsuite in Kali Linux

Hi, The installation screen was blank when I try to install burpsuite_community_linux_v1_7_29.sh in Kali Linux. Please advice. Thank you

Last updated: Dec 08, 2017 11:00AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Settings not saved in project

I can create a new project and change the options under scanner -> options -> active scanner optimization to Thorough and Normal. However, after closing the project and opening it again, these options are not saved and...

Last updated: Dec 06, 2017 02:32PM UTC | 4 Agent replies | 2 Community replies | Bug Reports

Unable to use higher unicode characters

I was unable to use higher unicode characters, such as russian letters, in repeter and proxy. I can't even edit POST body with content type application/json; charset=utf-8 Letters get substituted with letters with low...

Last updated: Dec 05, 2017 01:38PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Low: Typo in Advisory - HSTS Misconfig

Social mistyped - "If there is no HTTP server, an attacker in the same network could simulate a HTTP server and motivate the user to click on a prepared URL by a scoial engineering attack."

Last updated: Dec 01, 2017 02:15PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Cannot download big files.

Hi! I cannot download any big files through burp proxy. There is no cert installation mistake because I tried this on so many other employees devices too. There are no ssl errors too because a file smaller than 4 mb gets...

Last updated: Nov 25, 2017 04:00AM UTC | 5 Agent replies | 6 Community replies | Bug Reports

Burp 1.7.29 fails to create a project

BurpSuite Pro fails to create a new project on a updated Kali 2017.3. The error message in the GUI is "Failed to create Burp project: ExceptionInInitializeError" root@kali:/opt# java -version openjdk version...

Last updated: Nov 24, 2017 02:35PM UTC | 6 Agent replies | 6 Community replies | Bug Reports

URLs in target scope converted to lower case

When I add a URL like http://example.org/Dealer/A00123 to target scope it is converted to http://example.org/dealer/a00123. If I add it by 'Add to scope' in site map it works as expected but editing in scope tab converts...

Last updated: Nov 24, 2017 12:12PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

BApp Store Install hanging 1.7.28

The install of new extensions is hanging after upgrading from 1.7.27 to 1.7.28.

Last updated: Nov 17, 2017 10:03AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Memory overflow

Hi Guys. My Burp Pro always will be terminated by my kali linux, because it uses more then 4 GiB memory. I use 1.7.28, but the previous version (27) does the same thing. I run it from terminal like this: java -Xmx1g...

Last updated: Nov 16, 2017 05:00PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Freeze when changing issues severity

Hello, I am experiencing freeze with BurpPro. This happens when I try to change the severity of a SQL injection ScanIssue to FP. After, UI don't respond, Burp doesn't use CPU or change memory allocation. When launched...

Last updated: Nov 16, 2017 10:17AM UTC | 5 Agent replies | 2 Community replies | Bug Reports

Burp 1.7.28 does not load licenses

Hi there, Yesterday i upgraded BUTP suite PRO to 1.7.28 (from 1.7.27). The 1.7.28 could not recognize the license from 1.7.27 and has been asking for a new license. However, loading a license file endS in license not...

Last updated: Nov 16, 2017 09:29AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

'--project-file' Pauses Scanner

I made a post a week ago (here: https://support.portswigger.net/customer/portal/questions/17180858-save-project-file-with-burp-api) about automatically saving the project file. I was told about the --project-file...

Last updated: Nov 09, 2017 11:08AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Drop down menu bug

In some cases, when burp presents a drop down menu with previous used values (for example when filling in the Fixed time trottle in the options of intruder), the white "block" which is an empty drop down menu does not...

Last updated: Nov 08, 2017 11:13AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Page 127 of 142

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image