The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Installion Error

In Static members: In action "Backup agent.config file [Run script]" (screen "Installation location"), property "Script": java.nio.file.InvalidPathException: Illegal char <:> at index 10: ${compiler:release.version} at...

Last updated: Aug 09, 2019 12:59PM UTC | 5 Agent replies | 6 Community replies | Bug Reports

questions for bugs

How much does it take to find a bug using burpsuite? And is there a reason why i cant find any? Thanks!

Last updated: Jul 31, 2019 08:15AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp hotkeys are not working

- Ubuntu 18.04 - Burp Suite Pro For some reason Burp doesn't receive Ctrl + [A-Z] hotkeys, but Ctrl + [0-9] work just fine. Restoring defaults and reinstalling Burp doesn't solve the issue. Seems more like a system...

Last updated: Jul 29, 2019 12:41PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Not able to intercept one application using https

Dear Team, I am not able to intercept one application which is using https(Please note : Burp works perfectly fine with other HTTP's application) Getting below errors is burp's error logs:- - Attempting to auto select...

Last updated: Jul 29, 2019 07:26AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Web server's SSL (HTTPS) does not agree with Firefox 62

Firefox 62 offers the following "cipher suites" TLS_AES_128_GCM_SHA256 (0x1301) TLS_CHACHA20_POLY1305_SHA256 (0x1303) TLS_AES_256_GCM_SHA384 (0x1302) TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256...

Last updated: Jul 28, 2019 05:13PM UTC | 5 Agent replies | 3 Community replies | Bug Reports

Burp not reporting XSS issues

I've been using Burp for about 2 years, and Burp has been great at reporting XSS on our websites. It does not report it via normal scanning (1.x), it would report the issue if i found a XSS manually using proxy intercept....

Last updated: Jul 26, 2019 03:45PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp v1.7.24+ NTLM Issues

A large number of our app testing consultants at SecureWorks have noted that NTLM authentication stopped working once we upgraded past Burp v1.7.23. We have had to downgrade versions to get things working smoothly with NTLM,...

Last updated: Jul 25, 2019 03:02PM UTC | 4 Agent replies | 4 Community replies | Bug Reports

Crawl/Audit detailed scope configuration does not persist when selected from library

When performing a Crawl+Audit or Crawl, Scan details > Detailed scope configuration > Included URL prefixes, changes are saved if typed manually but not if populated by "Select from library". The url list appears correctly...

Last updated: Jul 23, 2019 01:26PM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Content-Disposition: attachment downloads do not render

Hi, image file (jpegs) downloaded with the response header Content-Disposition: attachment does not have a render tab in the new version of Burp. This means that you cannot see the images within Burp. An example response...

Last updated: Jul 23, 2019 01:04PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Client SSL Certificate - Hardware Token not detected

I am using the newest Burp version 2.1.01 on Microsoft Windows and want to use a hardware token / smart card for authenticating with a client SSL certificate. The PKCS #11 library is successfully found and loaded, but...

Last updated: Jul 23, 2019 06:42AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Error starting scan on Burp: Not all seed URLs are in scope

Hi, We're running Burp Suite Enterprise v1.0.15beta and use the HTTP API to register sites for scanning during nightly builds. The sites are registered based on endpoints extracted from swagger files (OpenAPI) and...

Last updated: Jul 22, 2019 01:25PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Burp Extensions

Hi, it's just a question and also a bug reports. I've noticed that in Burp v2 some api for extension were changed. and i've noticed this in Active scans phases. Many extension active scans fail to execute. Is there...

Last updated: Jul 22, 2019 01:22PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

SSL hardware certificate library cannot be loaded

To pentest applications using Belgian eID smart card identification and Burp Suite Pro, we import the Client SSL Certificate under the 'User Options'-tab > 'SSL'-tab by clicking the 'Add' button and selecting 'Hardware token...

Last updated: Jul 18, 2019 10:39AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Burp Pro 2.0.05beta Dynamic analysis injected values do not match reported value reaching sink

This is being reported as Client-side JSON injection (DOM-based). The value injected does not match the value that is reported as reaching the sink. Dynamic analysis Data is read from input.value and passed to...

Last updated: Jul 17, 2019 01:04PM UTC | 3 Agent replies | 1 Community replies | Bug Reports

An internal error occurred while launching Burpsuite jar and exe on windows machine

An internal error occurred while launching Burpsuite jar and exe on windows machine even i tried re downloading but not working. Burpsuite 1.7.35 is working but not 2.1.*

Last updated: Jul 16, 2019 12:25PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

repeater not work for https

intercept on,get https requests(A),send to repeater(B),in [Repeater] click [go],response status code:411.Now,in [Proxy] click [Forward],its work,in [HTTP history] response status code :200.Last,in [Repeater] click [Copy...

Last updated: Jul 16, 2019 09:19AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

[Beta v2.0.03beta] Exporting report - report title cache not working

Hi, A small bug it seems. When creating a report, in the reporting wizard window, when customising the report title and entering a title starting with the same letters/words that you used for previous reports, you will...

Last updated: Jul 10, 2019 02:13PM UTC | 2 Agent replies | 0 Community replies | Bug Reports

REST API Does Not Set Content-Type Header When Invoking Callback

When Burp's REST API issues a PUT request to the callback supplied to /scan, Burp does not set the Content-Type header. This causes issues when trying to integrate various tooling, such as ASP.NET Core 2.0. The platform...

Last updated: Jul 10, 2019 01:47PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

subject

<script>alert('hi')</script> <script>alert('hi')</script>

Last updated: Jul 10, 2019 11:59AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

localhost - worker process - not in burp - MAC OS

I currently use Chrome with SwitchySharp extension for Proxy or firefox with proxysetting into firefox. Everytime I try to catch traffic comming from localhost, it does not work. I must add an host to my etc/host to test...

Last updated: Jul 10, 2019 08:06AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Page 127 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image