Burp Suite User Forum

Create new post

Very simple file traversal found manually in repeater, but nothing in Burp Dashboard or Issues.

Just wondering what I might be doing wrong. Last week, doing a pentest on a business webapp & API and burp found a classic traversal -> ../../../../../../etc/passwd. I manually test the finding on the concerned API, and yes,...

Last updated: Oct 04, 2022 10:16AM UTC | 3 Agent replies | 3 Community replies | Bug Reports

burp crashes without any error on active scan

burp crashes without any error on active scan running. When run again same project crashes after some time again. com.sun.net.ssl.requireCloseNotify false exe4j.consoleCodepage cp0 exe4j.isInstall4j ...

Last updated: Oct 03, 2022 10:42AM UTC | 3 Agent replies | 5 Community replies | Bug Reports

Burp Collaborator SMTP Interaction Failure

OS: Linux JAR: 2022.8.4 Hi! I've set up a Collaborator server following the Portswigger guidance, and now have a successfully deployed instance that allows us to catch call back nicely. No port changes were made, and the...

Last updated: Oct 03, 2022 08:04AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Web Cache Poisonng labs

Hi, I was working with the labs on the topic "Exploiting cache implementation flaws" https://portswigger.net/web-security/web-cache-poisoning/exploiting-implementation-flaws I could not solve almost any of them because...

Last updated: Oct 03, 2022 07:51AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

An error occurred. We apologise for the inconvenience.

Hi, when I try to log in after I get a free trial, I get this error " An error occurred. We apologize for the inconvenience. "

Last updated: Oct 03, 2022 07:41AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

An error occurred. We apologise for the inconvenience.

Hi, when I try to log in after I get a free trial, I get this error " An error occurred. We apologize for the inconvenience.

Last updated: Oct 03, 2022 07:19AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Web Cache Poisonng labs

Hi, I was working with the labs on the topic "Exploiting cache implementation flaws" https://portswigger.net/web-security/web-cache-poisoning/exploiting-implementation-flaws I could not solve almost any of them because...

Last updated: Sep 30, 2022 03:30PM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Active Scan Selecting Individual Issue Doesn't Work Properly

I am configuring an active scanner configuration and selecting individual issue let's say only Cross-site Scripting(stored) but scanner is still sending payloads for SQL Injection, OS Command Injection, Path Traversal, etc.

Last updated: Sep 30, 2022 12:41PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Constant corrupted file warnings

I'm working with a project and every evening I properly close burp. When I open it in the morning, it states it's corrupted. I then repair it and use the repaired copy. This procedure has gone on for three days now. I have...

Last updated: Sep 30, 2022 08:34AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

account information issue

I'm not enable to access my account information to get my license key. An error page appeared with message "An error occurred. We apologise for the inconvenience."

Last updated: Sep 29, 2022 12:31PM UTC | 2 Agent replies | 2 Community replies | Bug Reports

https error

hello team i am using genymotion android version 7.0 and tried 7.1 as well i am not able to intercept requests due to https error (the connection is untrusted) I have added certificate already still its happening please...

Last updated: Sep 29, 2022 07:59AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burp suite scan reports vulnerability "Session token in URL"

Hi, Regarding above subject, CSRF token is being sent in the URL but I am not able to conclude this as valid defect. help me here to understand more on this issue. Reported issue misguides me as session token in the URL...

Last updated: Sep 28, 2022 10:34AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp's browser causes my system to freeze/log out of session

Hello guys, I was running the latest version of kali linux(2022.3) on my machine, and burpsuite community was working fine. Until this week when i tried to use the intercept feature, I opened the browser, and whoop! I got...

Last updated: Sep 26, 2022 09:20AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Unknown Host

Hello, Please help me out. Trying to use Burp on my firefox and it keeps on giving me "Unknown Host" error. Please, what do i do?

Last updated: Sep 23, 2022 11:17AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Burp Keep Asking for License

Hello Team It appears that burpsuite keeps prompting me to enter the license each time I logged in into burpsuite, I'm using my organization key and I'm using Mac M1 with latest version Hope to have some insight...

Last updated: Sep 23, 2022 08:52AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

"Specific labs" issue

Hello, On my dashboard (https://portswigger.net/web-security/dashboard) I see that I've completed all available labs, but in "Exam preparation steps" portswigger says' that I've not yet finished only 1 lab of 7. That is...

Last updated: Sep 22, 2022 08:56AM UTC | 2 Agent replies | 0 Community replies | Bug Reports

The .burp files are getting corrupted continuously even after repair

I'm using the latest version of Burp Pro and every day I'm facing this issue. The .burp files are getting corrupted continuously even after repair every single day. It seems I'm not the only one having this issue.

Last updated: Sep 22, 2022 06:48AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Error/bug/issue in the Intruder attack UI

Hello! working on his big Academy, he was trying to send some payloads in the request header (changing the value of TrackingId on each iteration). Like this: Cookie: TrackingId=dasdsadas' AND SUBSTRING((SELECT password...

Last updated: Sep 20, 2022 12:36PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Decoder-Copy/Paste not optional

Good day; I'm running Parrot OS 5.1 (Electro Ara) as guest via KVM Virt Manager. On top of Garuda Linux 5.19.9-zen1-1-zen KDE Plasma 5.25.5. With Burpsuite v2022.8.4 that came with the Parrot update. When firing up Burp I...

Last updated: Sep 19, 2022 04:11PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

502 error when site is added in scope

Hello there, I am getting some 502 error anytime i add the site in scope using the embedded chrome browser. As soon i remove the site from scope then all seems to be working but cannot add anything in the scope that i am...

Last updated: Sep 19, 2022 04:10PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Page 40 of 143

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image