The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Prototype Pollutions DOM Invader

Hi, I was trying to use DOM Invader to automatically find the way to solve the following exercises: Client-side prototype pollution in third-party libraries, DOM XSS via an alternative prototype pollution vector and...

Last updated: Jul 05, 2023 10:10AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Broken Lab: Visible error-based SQL injection

This lab was broken, it kept on giving same the error message: "Unterminated string literal started at position 95 in SQL SELECT * FROM tracking WHERE id = 'jUp8oNzaKr4pzj9y' AND 1 = CAST((SELECT password FROM users L'....

Last updated: Jul 05, 2023 09:16AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Section Symbols are appearing in images which breaks Intruder

Section Symbols '§' are appearing in any images (jpg, gif, png, etc.) when retrieved in GET requests or posted in POST, if sent to Intruder it corrupts the image because it strips those characters.

Last updated: Jul 05, 2023 08:58AM UTC | 5 Agent replies | 5 Community replies | Bug Reports

section symbole isuue

hi when i using intruder i have isuue with section symbole(§) There is the same symbol in my Arabic language, which causes interference and problems in the work of the intruder, can we change section symbol (§) with other...

Last updated: Jul 05, 2023 08:52AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Question/bug on lab "CORS vulnerability with internal network pivot attack"

While trying to solve the mentioned lab, the retrieved HTML code from the internal website cleary states that the request for the "login" is a POST. However, the solution silently continues with a GET to trigger the XSS. If...

Last updated: Jul 05, 2023 08:28AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Solved

The post you are implying about is my solution for all the set labs and solved all problems including bug labs Apetree1001@email.phoenix.edu

Last updated: Jul 05, 2023 06:25AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

2FA bypass using brute-force attack

I'm not able to solve this lab using turbo intruder as I'm using burp suite community edition. I also try to check if this issue persist only with turbo intruder or normal intruder, but this issue also happens with normal...

Last updated: Jul 04, 2023 10:01AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Problem with license key Enterprise Edition

Dear team, I requested for trial version of Enterprise edition. I have received the required info and i have followed the steps on portswigger as well but the moment i upload the license key it is throwing me an error -...

Last updated: Jul 04, 2023 09:47AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Invalid certificate generated

The certificate generated contains a country code of PortSwigger which does not conform to the RFC which says that the country code should have a length of 2 https://datatracker.ietf.org/doc/html/rfc3280#page-96 This...

Last updated: Jul 04, 2023 08:59AM UTC | 7 Agent replies | 7 Community replies | Bug Reports

Intruder Payload processing

if i use Payload processing: hash:MD5 on result page i see hashed payloads. One of them "good" but i can't see in "raw" only hashed. Screenshot: https://i.imgur.com/X0Mxku3.png p.s. in this task i must brute-force...

Last updated: Jul 03, 2023 01:12PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

my burp tip Unsupported or unrecognized SSL message

Using burp embedded browsing to visit the website to prompt certificate problems

Last updated: Jul 03, 2023 09:15AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Link manipulation (DOM-based) - JQuery

Hi all, we use jquery-3.3.1.js in our application. Burp scan found a Link manipulation (DOM-based) vulnerabilities in JQuery sources: 1. // Anchor tag for parsing the document origin originAnchor =...

Last updated: Jun 30, 2023 08:39AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

CSRF where token validation depends on request method and

Hi, The lab seems to have a bug in it. When I submit Store, View Exploit and Deliver exploit to victim. The Lab is not getting solved. Please fix. Thanks, Suresh

Last updated: Jun 30, 2023 05:45AM UTC | 1 Agent replies | 2 Community replies | Bug Reports

CSRF where token validation depends on token being present

Hi, The lab seems to have a bug in it. When I submit Store, View Exploit and Deliver exploit to victim. The Lab is not getting solved. Please fix. Thanks, Suresh

Last updated: Jun 30, 2023 05:44AM UTC | 1 Agent replies | 2 Community replies | Bug Reports

The client failed to negotiate a TLS connection to <domain>:443: Remote host terminated handshake

Since a couple of month I am receiving this error quite randomly when trying to reach some standards site of my customers. Some times sites are working and other times not (and may be the same site). I am using burp pro...

Last updated: Jun 29, 2023 07:12AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Weird behavior when trying to close the last tab in Intruder and Repeater

Good afternoon, Burp Suite Community Edition v2023.5.4 [p4629zecilnjzve8msrj:19nf] When a user tries to close the last tab in the "Intruder" or "Repeater" by pressing the "x" on the tab, instead of the tab closing,...

Last updated: Jun 28, 2023 09:16AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Activation Failed error

Hi, We bought the burpsuite professional since May 2022. We have purchased 3 units of license for 3-years (i.e. license expires on May 2025). We have been using the software without any issues until recently. When we try...

Last updated: Jun 28, 2023 09:15AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: Browser cache poisoning via client-side desync, cannot be reproduced locally in the final step due to parsing abnormalities.

The task can only be completed using the following script and "Deliver exploit to victim". cannot be reproduced locally by clicking View exploit. Therefore, I believe this lab is incomplete or has an...

Last updated: Jun 28, 2023 06:41AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: SameSite Strict bypass via sibling domain

Please check if any update was done on your part for the mentioned lab. In proxy history there are no requests for resources like script and image files containing an Access-Control-Allow-Origin header, which reveals a...

Last updated: Jun 26, 2023 08:04AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp Suite Mobile Assistant require updates

Hi, I am running iOS 12.4.4 and I want to use Mobile Assistant to bypass SSL Pinning as SSL Kill Switch 2 cannot bypass with the app that I wanted to test. When I launch Mobile Assistant, the app require updates to support...

Last updated: Jun 25, 2023 02:36PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Page 35 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image