Burp Suite User Forum

Create new post

File Upload Lab not working

Hello, it seems to me that the first lab (remote code execution via web shell upload) is not working correctly. I managed to print the contents of /home/carlos/secret but when I submit it says wrong solution

Last updated: Sep 14, 2024 06:07PM UTC | 2 Agent replies | 4 Community replies | Bug Reports

Copy/Paste not working

I work in web security in Korea and have been a long-time user of Burp products. Primarily, I use them on MacOS. I report bugs not only because they inconvenience me but also because my colleagues are experiencing the same...

Last updated: Sep 14, 2024 11:41AM UTC | 10 Agent replies | 11 Community replies | Bug Reports

Running BurpSuiteCE on Parrot 6.1

Hi there, I've just installed Parrot OS on my macBook (UTM). Everything has been updated, however I cannot run Burpsuite. I get the following message: java.lang.UnsupportedClassVersionError: burp/StartBurp has been...

Last updated: Sep 13, 2024 08:39PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Shortcut Keys don't work

Hi, The shortcut keys (e.g. ctrl-C, ctrl-v) don't work in the new releases. Please fix. Thanks, Carl

Last updated: Sep 13, 2024 02:00PM UTC | 4 Agent replies | 7 Community replies | Bug Reports

Cannot re-disable logging out-of-scope items to the history

Hi, when I created new project, caught several requests and added the selected into scope, I was offered the option to disable logging out-of-scope items to the history and I confirm it. It worked and there was a warning...

Last updated: Sep 12, 2024 02:13PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

getRequest() and getResponse() methods not called in the new Intercept interface

Hi, I noticed that with the new Proxy Intercept interface, when you intercept a request/response, open a custom tab (e.g. the one in your examples...

Last updated: Sep 12, 2024 01:29PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Cannot update Burp

Hi I'm trying to update my Burp to version v2024_7_5. Usually it wad done automatically by Burp. This time it didn't work. I tried to do it manually by download file from portswigger and exec installer. It didn't work...

Last updated: Sep 12, 2024 09:57AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

burp community-failed to connect to website.com:443

Hi, I'm trying to connect to website using burp chromium browser. But most of the time, the loading end by an error screen saying "failed to connect to website.com:443" I searched but didn't fought any awnser that helped...

Last updated: Sep 12, 2024 08:23AM UTC | 4 Agent replies | 4 Community replies | Bug Reports

Burp would change hex values of non-printable characters in binary files in POST request (repeater/intercept)

Hi, I'm on version v2024.7.5 I encountered bug in intercept and repeater. When editing POST request that has attached in body binary file like xls. After modyfing as little as one character in "pretty" and "raw" tab in...

Last updated: Sep 12, 2024 08:17AM UTC | 4 Agent replies | 3 Community replies | Bug Reports

Send to Intruder inserts character markers at incorrect positions when executed from the GraphQL message editor tab

Bug overview: Intruder markers are added to the wrong character positions when the "Send to Intruder" action is executed while selecting text in the new GraphQL message editor tab. The Intruder markers appear to be inserted...

Last updated: Sep 11, 2024 02:19PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Issue with Burp Suite Version 2024.7.5 - Crashing During RDP Sessions

We have encountered an issue with Burp Suite Professional version 2024.7.5 where the application crashes while connecting through RDP. This issue significantly affects our workflow, as we heavily rely on remote sessions for...

Last updated: Sep 11, 2024 11:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Nothing happens when I click on the "Open browser" button

Hello all, I use Ubuntu 24.04 LTS (with gnome 3). I have downloaded the last version (30 august 2024) which is burpsuite_community_linux_v2024_7_5.sh When I click on the "open browser" button, nothing...

Last updated: Sep 11, 2024 10:24AM UTC | 1 Agent replies | 3 Community replies | Bug Reports

Scanner Is it a bug? "Cross-domain Referer leakage" is reported despite no sensitive data in the "Referer" header, why?

Hi team, Need some clarifications on this scanner category "Cross-domain Referer leakage". My client needs to use this burp pro scanner feature. Burp Pro scanner reports "Cross-domain Referer leakage" even no...

Last updated: Sep 11, 2024 09:32AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Exploiting insecure output handling in LLMs not solving

seems that the lab Exploiting insecure output handling in LLMs i have also tried the sugested solution. if i ask for the review it delete my profile but is like carlos is never asking info about the l33t product.

Last updated: Sep 11, 2024 07:29AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

"Cross-domain Referer leakage" is reported despite referrerpolicy attribute

Hello, an active scan on one of our applications reports a "Cross-domain Referer leakage". Taking a look at the response tab in Burpsuite, the following snippet is highlighted: <a class="info-box" target="_blank"...

Last updated: Sep 11, 2024 01:19AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Can't start BSCP Exam

Hello, I purchased access to the BSCP exam today, I'm going through the process for the second time. I passed the initial session on the Examity portal and when I try to start the exam on the examiner's page, I see the...

Last updated: Sep 10, 2024 08:23AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

LAB Not solved

Labs are not getting in solved status even after taking the right approach or the suggested approach in the exercise. 1.Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and...

Last updated: Sep 10, 2024 08:18AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab status bug

Hi team, So far, I have observed this unsloved to solved status bug. Even if you do the labs correctly, the lab doesn't gets solved. 1.Reflected XSS with some SVG markup allowed 2.Reflected XSS into a JavaScript...

Last updated: Sep 10, 2024 08:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: CORS vulnerability with basic origin reflection not working

In this lab, I'm stuck on step 5 of the solution: In the browser, go to the exploit server and enter the following HTML, replacing YOUR-LAB-ID with your unique lab URL: <script> var req = new XMLHttpRequest(); ...

Last updated: Sep 10, 2024 06:23AM UTC | 18 Agent replies | 27 Community replies | Bug Reports

2024.7.5, Montoya API, Extensions, Custom Editor Tab, Modified Requests Not Forwarded

I have received a bug report about our SAMLRaider extension that the modified requests are not being forwarded correctly. This problem occurs with the new BurpSuite version 2024.7.5. I can reproduce the bug, but I am not...

Last updated: Sep 09, 2024 04:36PM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Page 2 of 152

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image