Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
I tried changing some of proxy settings uninstalling and reinstalling, changing port and address but nothing worked and I don't know why.
Hello, I need help solving this problem. Every time I close and reopen Burp, I have to delete the old certificate and regenerate a new one. If I don’t do this, I keep getting a "Secure Connection Failed" error. How can I...
I have noticed, if i highlight and/or comment some items from attack result table and try to filter them by these annotation, it doesn't work. I have faced this in version : "burpsuite_community_linux_v2023_2_3.sh". I have...
Hello, the victim in the lab in the object does not seems to visit the exploit page when clicking on "Deliver exploit to victim button". I've experienced the same problem with multiple laboratory instances but it seems to...
This labs seems to be broken. Normally it should have a time limit of 15 minutes. Yesterday I started the lab, but it started the lab with 00:00 time. This morning I tried again, same 00:00 time. I also don't see the option...
Hi, I would like to know if there are any way that I can get Burp Browser to pass Cloudflare Turnstile verification. The website I am testing (www.example.com) uses an OAuth2.0 login from a different site...
Lab on the "CORS vulnerability with trusted insecure protocols" seems to now work. Payloads tested: <script> ...
Hi Burpsuite team, I just installed the new Burpsuite version, 2024.9, and noticed that in the "HTTP match and replace rules" section, the Add and Edit buttons do not work. I restarted Burpsuite but the problem...
I used a private repo (hence not sharing) OpenAPI .yaml spec to augment a collection, then used redocly-cli to create a v3.1 SON collection and then used @apiture/openapi-down-convert (npm) to downgrade the v3.1 OpenAPI spec...
Hi all I’ve encountered an issue recently that I believe reflects a change in behaviour when testing CORS request blocks. In the past, when I needed to test CORS, I would make modifications and use Burp's "In-Browser...
Tried https://skullhat.github.io/posts/reflected-xss-protected-by-very-strict-csp-with-dangling-markup-attack/ and customized script <script> ...
I tried everything and it is not working i even tried chrome and firefox both are not working LAB:CSRF where token validation depends on request method my code : <html> <!-- CSRF PoC - generated by Burp Suite...
Hi, first I want to thank you for these awesome labs! They really rock! Unfortunately I think something is wrong with this challenge:Reflected XSS with some SVG markup allowed. I am able to trigger an alert box, but it...
Hello support, I regularly install new instances of Burp Suite every few months for operations. However, I recently ran into a problem trying to activate a new instance. Any help would be appreciated.
When using the Proxy HTTP History, the request and response viewing panes stop updating after a period of use. The selected request is highlighted in the top pane, but this does not change the contents of the view panes...
For multiple labs, the exploit is being delivered to the victim, however, the exploit server logs don't show the victim user actually clicking on the exploit. Sometimes, this resolves automatically, however, in multiple...
I have a project files which was corrupted owing to a power cut. Burp went through the repair process, but when opening the repaired file the Proxy tab is missing and the event log shows a message: Error...
Adding or Editting custom column hints breaks UI if a tooltip is displayed while typing. To reproduce; go to Proxy History, click the meatball menu, click Add Custom Column. Type the following (it is important to type...
For some reason random HTTP requests will only show the response with the request pane hidden until I drag the slider to reveal it. Most requests and responses are fine. I can see no pattern to this. Running 2024-8-1 32184...
Here is my cache poisoning / Smuggled request POST / HTTP/1.1 Host: 0a16007d0305e2b380340869000b001a.web-security-academy.net Content-Type: application/x-www-form-urlencoded Content-Length: 185 Transfer-Encoding:...
Page 4 of 156
Your source for help and advice on all things Burp-related.