The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp Collaborator WAF triggering/not obeying options

Hey, I am currently using Burp to run an assessment on a website. They use Incapsula as a WAF, which is being triggered very frequently. At first I thought it might be related to spidering too fast, but I modified the...

Last updated: Feb 12, 2018 10:02AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Received Fatal Alert: Handshake_Failure

Hi, I am a Burp pro user. My Burp pro throws an error in web screen and Alert tab in the burp like the subject: Received Falat Alert: Handshake_Failure. Firstly, I need to tell you that I took the certificate from...

Last updated: Feb 09, 2018 07:12AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

PortSwigger Certificate invalid

(I'm using macOS High Sierra 10.13.3 and Burp Suite Community Edition v1.7.32) I've followed the instructions to install the Burp Certificate...

Last updated: Feb 05, 2018 08:16AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

IParameter Flags

The flag fields in IParameter are set to default visibility. I'm guessing they are intended to be public.

Last updated: Feb 05, 2018 08:08AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

problem

"><a href="javascript:confirm%28 1%29">Clickme</a>

Last updated: Jan 24, 2018 07:51AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Burp import project

Thanks for the new "Burp import project" feature. Burp requires that you have a disk-based project to be able to import projects after opening Burp. So if you have a temporary project then you cannot import. When you...

Last updated: Jan 23, 2018 03:30PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Scanner Issue Activity import project

When importing a project the scanner issue activity remained empty, no issues were imported. However, when opening the same project normally (during start up of Burp), all of the issues populated the scanner issue...

Last updated: Jan 23, 2018 03:29PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Not able to upgrade the Burp Suite from v1.7.07 to 1.7.30

I have Burp Suite of version v1.7.07 installed on machine now wanted to upgrade it to the latest version 1.7.30 I clicked on 'Update Now' button, downloading is completed till 100% but nothing will happen then. Please...

Last updated: Jan 16, 2018 05:52AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Excluded scanner issue still showing up in report

Using 1.7.30 Minor thing here... I excluded a bunch of individual scan issues and ran a scan. In the final results, I still had "Python code injection" showing up in the results of issue types, even though it was excluded.

Last updated: Jan 10, 2018 08:48AM UTC | 3 Agent replies | 4 Community replies | Bug Reports

Intruder not starting a saved attack

Hi All I have been running an intruder attack and saving periodically and restarting without issues. However following a necessary save, reboot and resume i have been unable to get intruder to successfully open the saved...

Last updated: Jan 05, 2018 03:39PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Issue type vs Issue name uniqueness in scanner XML output

Hi team, I'm working on the Burp parser for Dradis (http://dradisframework.org) and one of our users has reported an issue with the way two different findings are reported under the same Issue type number. It seems...

Last updated: Dec 27, 2017 04:34PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp Suite generates "weak ephemeral Diffie-Hellman key" error with Firefox Developer Edition

I've been using Burp Suite with Firefox Developer Edition, but as of today, I cannot make HTTPS connections when using Burp Suite as a proxy. I now get the following error message: An error occurred during a connection to...

Last updated: Dec 19, 2017 10:16AM UTC | 4 Agent replies | 11 Community replies | Bug Reports

Burp Intruder Missing Delimiter

Hi, I have seen an unexpected behaviour in Burp when using Intruder and fuzz points. Within the Intruder you can define fuzz points via the § character, however, you don't have to use two of them. If only one § is used,...

Last updated: Dec 19, 2017 08:48AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Bug in Scanner Issue Activity

In my current project the greatest ID is 2634. At some point burp decided to continue the counting from around 1000 and I don't know whether it overwrites my existing vulnerabilities. This behavior has been noticed only on...

Last updated: Dec 13, 2017 12:03PM UTC | 4 Agent replies | 3 Community replies | Bug Reports

Burp API - IContextMenuInvocation - Modified request/response access/hinting

In the Burp extender API when retrieving the selected messages from the proxy history, I don't see any way to know if the selection occurs into a modified response/request panel or the original one....

Last updated: Dec 12, 2017 04:35PM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Encounter blank screen when installing burpsuite in Kali Linux

Hi, The installation screen was blank when I try to install burpsuite_community_linux_v1_7_29.sh in Kali Linux. Please advice. Thank you

Last updated: Dec 08, 2017 11:00AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Settings not saved in project

I can create a new project and change the options under scanner -> options -> active scanner optimization to Thorough and Normal. However, after closing the project and opening it again, these options are not saved and...

Last updated: Dec 06, 2017 02:32PM UTC | 4 Agent replies | 2 Community replies | Bug Reports

Unable to use higher unicode characters

I was unable to use higher unicode characters, such as russian letters, in repeter and proxy. I can't even edit POST body with content type application/json; charset=utf-8 Letters get substituted with letters with low...

Last updated: Dec 05, 2017 01:38PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Low: Typo in Advisory - HSTS Misconfig

Social mistyped - "If there is no HTTP server, an attacker in the same network could simulate a HTTP server and motivate the user to click on a prepared URL by a scoial engineering attack."

Last updated: Dec 01, 2017 02:15PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Cannot download big files.

Hi! I cannot download any big files through burp proxy. There is no cert installation mistake because I tried this on so many other employees devices too. There are no ssl errors too because a file smaller than 4 mb gets...

Last updated: Nov 25, 2017 04:00AM UTC | 5 Agent replies | 6 Community replies | Bug Reports

Page 140 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image