Burp Suite User Forum

Create new post

getSelectionBounds() function return wrong indexes when message contains Chinese

I try to get selected content with function "getSelectionBounds()". but I found it return wrong indexes when message contains Chinese, and Chinese is in front of the selected. here is the code of test: source =...

Last updated: Jun 08, 2023 07:03PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Montoya API NoSuchMethodError

When loading an extension that uses the burp.api.montoya.ui.menu.MenuItem.basicMenuItem method, I receive the following exception: java.lang.NoSuchMethodError: 'burp.api.montoya.ui.menu.BasicMenuItem...

Last updated: Jun 08, 2023 03:26PM UTC | 5 Agent replies | 5 Community replies | Bug Reports

net.portswigger.devtools.client.impl.connection.local.Zo: Unpacking the BurpBrowser binaries failed because the chromium-linuxarm64-114.0.5735.90.zip archive was not found on the classpath

Hello I have an iMac M1 and work with Parallels and Kali Linux as VM. There I installed burpsuite with sudo apt install burpsuite, but I cannot open the Browser. I cannot insert the screenshot which I have made. What...

Last updated: Jun 07, 2023 04:28PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Visual Glitches within Burp, on secondary screen

Hello, For the last couple of versions, I have encountered weird visual glitches of Burp Suite. Video showing the issue: https://www.youtube.com/watch?v=BgXuIyel_MI At 0:40, it even shows the content of the other Burp...

Last updated: Jun 07, 2023 08:33AM UTC | 6 Agent replies | 8 Community replies | Bug Reports

Lab: Cache key injection

Hi, I can't solve the lab. I am sending the following requests, ----- 1. ----- First request (Please note that the Origin header has been added 2 times): GET /js/localize.js?lang=en?utm_content=z&cors=1&x=1...

Last updated: Jun 07, 2023 08:12AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Data is read from window.location.href

Hi We find this issue in one of our websites and we think that is a false positive. Data is read from window.location.href and passed to the 'append()' function of JQuery via the following statements: - url =...

Last updated: Jun 06, 2023 12:33PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

CSRF problem with lab

the lab called "CSRF where token is tied to non-session cookie" https://portswigger.net/web-security/csrf/bypassing-token-validation/lab-token-tied-to-non-session-cookie has a problem.I put this code on the body of the...

Last updated: Jun 06, 2023 08:52AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp Intruder Payloads options simple list section not working

Burp Intruder Payloads options simple list section is not allowing me to: 1. Add from list 2. Load custom payloads

Last updated: Jun 06, 2023 08:45AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Community Sollution Youtube video is wrongly merged in Access control lab

In Web Security Academy on Access control Topic, The 3rd Lab which is been provided with two you-tube video for community solution. The Second Video "Which is been Michael Sommer sir video" that video is the solution of 4th...

Last updated: Jun 05, 2023 10:26AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Class Not Found: burpsuite_community_v2023.5.2.jar with Java 17

$ uname -a Linux kali-raspberry-pi 5.15.44-Re4son-v7l+ #1 SMP Debian kali-pi (2022-07-03) armv7l GNU/Linux $ java -jar -Xmx2g burpsuite_community_v2023.5.2.jar Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on...

Last updated: Jun 05, 2023 07:11AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab PRACTITIONER Reflected XSS with some SVG markup allowed

Hello! I got popup window from alert() function in this lab, bit it does not marked as resolved lab. Something wrong? Payload - <svg><animatetransform onbegin=alert('hi')>

Last updated: Jun 02, 2023 06:58AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

DOM XSS in jQuery anchor href attribute sink using location.search source not solved

Lab is not solving whatever I can try to do, step by step tutorial doesn't help

Last updated: Jun 01, 2023 01:52PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

HTTP Response freezes in Intruder results table

Hi, For an intruder containing three results with status codes (200, 302, ...) How to reproduce: 1. Go to 'render' in http response of the first item - keep 'render' visible 2. switch to the item with status code...

Last updated: Jun 01, 2023 11:33AM UTC | 1 Agent replies | 3 Community replies | Bug Reports

.install4j\files.log (The system cannot find the file specified) Error While Uninstall

Hello people, I have installed burpsuite_enterprise_windows-x64_v2022_1.exe on windows server 2016 and now I want to uninstall it. However, when I run the uninstaller it gaves me an error like this and alert me it was...

Last updated: Jun 01, 2023 07:16AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

License is suddenly invalid, even though it should expire in November

Hello When opening the application this morning we found that BurpSuite is asking for the license key, and after providing the key that should be valid until November 2023 it says it's invalid. Logging on to the portal to...

Last updated: May 31, 2023 02:45PM UTC | 4 Agent replies | 5 Community replies | Bug Reports

Burp's CA certificate is expired

Hi, I'm able to reach out to http://burpsuite in Chrome. I downloaded CA Certificate -> cacert.der However, the file which I downloaded is the expired CA certificate which I'm not able to add to Keychain Access on...

Last updated: May 31, 2023 01:27PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Lab: HTTP/2 request smuggling via CRLF injection - truncated victim session

Hi, It seems impossible to fetch the victim's session because it always gets truncated (see at the end): <li> <a...

Last updated: May 31, 2023 10:45AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Cannot do offline activation anymore for Burp Pro

Dear PortSwigger support, We have a Burp Pro license (for 70 activation) for very long time. When installing Burp we are using the offline-activation feature but as of few weeks ago this does not work anymore; After...

Last updated: May 31, 2023 09:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: HTTP request smuggling, basic CL.TE vulnerability

I can't solve lab tried many times, help here is the code - POST / HTTP/1.1 Host: 0a90006303d9bbc387c5700800820036.web-security-academy.net Content-Type: application/x-www-form-urlencoded Content-Length:...

Last updated: May 31, 2023 06:53AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

cookie flags are raised in burpscan but not in manual testing.

burp scanner keeps raising the issue(s): - TLS cookie without secure flag set - Cookie without HttpOnly flag set. However, when replicating the same request manually (either by closing the session and re-opening, or...

Last updated: May 30, 2023 11:03AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Page 33 of 152

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image