The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp Professional Target tab: scope issue

Host OS Windows 11, burp version is Burp Pro v2023 5.4 Build 21196 Issue: Targets tab Scope filtering by in-scope targets not working when 2 similar domain entries are used as "in scope" Details: In burp...

Last updated: Jun 23, 2023 03:02PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Domains ending with a dot throw ssl error.

The most recent versions of chrome and firefox will load this URL with the `.` at the end of the domain: https://portswigger.net. In burp browser this throws an ssl error: This site can’t provide a secure...

Last updated: Jun 23, 2023 07:09AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

[BUG] Lab: DOM XSS in jQuery anchor href attribute sink using location.search source

The solution is hit the back button in "https://XXXXX.web-security-academy.net/feedback?returnPath=javascript:alert(document.cookie)" URL, exploring href unsanitized problem. Even so, the laboratory is not solved. I've...

Last updated: Jun 22, 2023 09:51AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Capturing uploaded packages on the mac book pro m1 is very clunky

Capturing uploaded packages on the mac book pro m1 is very clunky and even sometimes unresponsive, and the program must forcibly exit burp v2023.5.3

Last updated: Jun 21, 2023 08:44AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

issues with 'add to site map' feature in Repeater tab

Hi, been having this issue for the longest time and even now in the current release of burp pro. so what happens is when im testing an api through burp but the api collection or documentation is off, i would need to many...

Last updated: Jun 20, 2023 02:04PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

It seems like some release of the Jar files have the MacArm64 Chrome BurpBrowser and others don't

Using the Jar version on Mac there are inconsistencies with the embedded browser. Looking inside the Jar file on some versions there is an Arm64 browser and then some don't, even though I get an error that says unpacking the...

Last updated: Jun 16, 2023 09:37AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

License activation is failing.

Hello, The assigned Burp license file to Onetrust organization is not working. Please look into and resolve the issue at the earliest. Regards, Sharan

Last updated: Jun 15, 2023 01:27PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Bug in lab "Web cache poisoning via an unkeyed query parameter"

Hi, it seems that there is a bug in the lab "Web cache poisoning via an unkeyed query parameter". The response to GET / never gets cached as the server always return X-Cache: miss. Cheers, Jesús

Last updated: Jun 14, 2023 12:57PM UTC | 2 Agent replies | 4 Community replies | Bug Reports

Lab: Web cache poisoning via an unkeyed query string is making unexpected request.

In the stated lab when the home page is taken into the repeater, and added with Pragma: x-get-cache-key header & value, the response contains X-Cache-Key: /$$origin=https://gt2p587.com, here the value in the origin is...

Last updated: Jun 14, 2023 09:03AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Facing issues accessing labs

ID.web-security-academy.net took tooo long to respond ERR_TIMED_OUT tried relaunching multiple times yesterday and today too but still showing the same.

Last updated: Jun 13, 2023 02:12PM UTC | 4 Agent replies | 6 Community replies | Bug Reports

Issue with lab

Hi, Is there any ongoing issue with below lab: https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-exploiting-java-deserialization-with-apache-commons Lab is not getting solved even...

Last updated: Jun 13, 2023 07:53AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Failed to create Burp: project: Duplicate key ... ERROR (Ambiguous hotkey definition is possible, for CTR+SHIFT+LEFT/RIGHT)

Dear Developers, I'm really pleased with the Burp Suite Pro, but today I defined some new Hotkeys and Burp allowed me to do this for Ctrl+Shift+Left and Ctrl+Shift+Right even when THESE KEYSTROKES WAS ALREADY DEFINED....

Last updated: Jun 13, 2023 06:36AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Burp crashes, asking for license key on relaunch

Hi there! I've encountered something pretty odd today twice. I'm running the 64-bit Windows version of Burp Suite Pro (1.7.27) and the application just crashes. Upon relaunching, I'm prompted to enter my license key. I'm...

Last updated: Jun 12, 2023 06:55AM UTC | 5 Agent replies | 15 Community replies | Bug Reports

getSelectionBounds() function return wrong indexes when message contains Chinese

I try to get selected content with function "getSelectionBounds()". but I found it return wrong indexes when message contains Chinese, and Chinese is in front of the selected. here is the code of test: source =...

Last updated: Jun 08, 2023 07:03PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Montoya API NoSuchMethodError

When loading an extension that uses the burp.api.montoya.ui.menu.MenuItem.basicMenuItem method, I receive the following exception: java.lang.NoSuchMethodError: 'burp.api.montoya.ui.menu.BasicMenuItem...

Last updated: Jun 08, 2023 03:26PM UTC | 5 Agent replies | 5 Community replies | Bug Reports

net.portswigger.devtools.client.impl.connection.local.Zo: Unpacking the BurpBrowser binaries failed because the chromium-linuxarm64-114.0.5735.90.zip archive was not found on the classpath

Hello I have an iMac M1 and work with Parallels and Kali Linux as VM. There I installed burpsuite with sudo apt install burpsuite, but I cannot open the Browser. I cannot insert the screenshot which I have made. What...

Last updated: Jun 07, 2023 04:28PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Visual Glitches within Burp, on secondary screen

Hello, For the last couple of versions, I have encountered weird visual glitches of Burp Suite. Video showing the issue: https://www.youtube.com/watch?v=BgXuIyel_MI At 0:40, it even shows the content of the other Burp...

Last updated: Jun 07, 2023 08:33AM UTC | 6 Agent replies | 8 Community replies | Bug Reports

Lab: Cache key injection

Hi, I can't solve the lab. I am sending the following requests, ----- 1. ----- First request (Please note that the Origin header has been added 2 times): GET /js/localize.js?lang=en?utm_content=z&cors=1&x=1...

Last updated: Jun 07, 2023 08:12AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Data is read from window.location.href

Hi We find this issue in one of our websites and we think that is a false positive. Data is read from window.location.href and passed to the 'append()' function of JQuery via the following statements: - url =...

Last updated: Jun 06, 2023 12:33PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

CSRF problem with lab

the lab called "CSRF where token is tied to non-session cookie" https://portswigger.net/web-security/csrf/bypassing-token-validation/lab-token-tied-to-non-session-cookie has a problem.I put this code on the body of the...

Last updated: Jun 06, 2023 08:52AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Page 36 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image