Burp Suite User Forum
Burp Team, here is what's going on. I've just downloaded the Burp Suite Professional v1.7.03. When running it, a new window related to the new "project" feature opens. Whatever i select there, a temporary project,...
Hello, I am not able to run burpsuite pro 1.7.03 at my Linux machine. It crashes after I choose to create a new project and choosing "Use Burp Defaults" and pressing "Start Burp". This is my java version: # java...
I'm seeing behavior from the active scan check for "X-Forwarded-For dependent response" that changes the effect of the request and seems likely to produce false positives. When the scanner sends the request with the...
This affects both project and user JSON config files. At minimum, documentation warning of this would be good. Better yet, add an option to encrypt or not include them, like the save state file wizard has. If that's too much...
With version 1.7.03, using a temporary project or an existing project,then selecting a saved configuration file doesn't load the configuration setting from that file. Specifically the upstream and SOCKS proxy settings always...
Hola, I've just set up a new install of Windows 8.1 64-bit (fully patched) with the latest (AFAIK) versions of Java and Burpsuite (running as "java -jar -Xmx4096m burpsuite_pro_v1.6.14.jar" from a command prompt with...
I am Using Pro version of Burp Suite, I am unable to put check on Proxy Listeners. Please fix this issue.
I have a URL which is indicating a CSRF issue. When I attempt to select the URL and perform an active scan of the branch, I receive the following messages from the command window: D:\Tools>java -jar -Xmx2G...
Burp in version 1.7.02beta hangs indefinitely on an attempt to save a state in the existing file (overwrite). The whole UI starts to behave erratically and burp cannot be exited otherwise than being killed.
Using BurpSuite Pro 1.6.39. Scanner found an XSS and gave it "Informational" severity, so I read the "Issue Detail" a little more closely than usual (because why "informational"?) The Detail contains two nearly identical...
Hi I'm not able to create a new project when I specify that the location of the project file is within a shared folder on a Kali VM on Virtualbox. Specifying another 'local', location the creation of the project file...
Hi, We have a licensed version of Burp suite running and the license is issued to Cisco Systems India Pvt Ltd. We have been running Burp suite on our application and wanted to report an issue that we have been...
Hi There, I am using Burp Suite Professional v1.7.02 beta. There is a very issue in Live Scanning. Every time I select option Don't Scan in Live Passive Scanning and close the Burp Suite. Whenever I start Burp Suite...
Hello, the possibility to use a PKCS#12 keystore in the proxy certificate options saved our bottoms today in a SoapUI/Ready! API environment, so thanks for that first. [for other poor souls in the same situation: If...
I am having issues with the "Test in browser" functionality from CSRF PoC and "Show response in browser" functionality from proxy. Both of these seem to work fine with the default configuration of Burp set to listen on...
When an AMF response body contains a custom object, BURP can't seem to properly deserialize the body and return a "data - null" instead of the proper object. For the same request/response, Charles proxy seem to be able to...
Hello, I'm working on super basic extension which allows to edit the value of a specific cookie in its own Repeater display tab. But when I call updateParameter(..., buildParameter(..., PARAM_COOKIE)), the cookie line is...
Every issue that is created gets a first paragraph telling which extension it was: "Note: This issue was generated by the Burp extension: <extension name>" When an extension's issue gets more than one hit, a top-level...
We are working as a small team and my colleague gave me his saved burp state. I restored it in my burp instance mostly without problem, but the options/ssl tab fails to load properly. The site we are testing requires a...
Hi, Burp Scanner v1.6.38 gave me false positive for "Session token in URL" without any reason, as I think. Take a look at following excerpt from...
Page 130 of 137
Your source for help and advice on all things Burp-related.