The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: HTTP request smuggling, basic TE.CL vulnerability

I am running through the labs again in prep to take the test. I think this lab has stopped working. Regardless of what I do, it does not seem like the backend is honoring the Content-Length header. I've tried multiple...

Last updated: Sep 20, 2024 10:25AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Install Script Leaks the java binary

The Download and Install Bash script for arm Linux when you install Professional Burp suite is leaks the java bin. -- output: └─$ bash burpsuite_pro_linux_arm64_v2024_7_6.sh > Unpacking JRE ... > Starting Installer...

Last updated: Sep 19, 2024 02:49PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Cannot set up Chromium DevTools overrides in embedded browser

When I open DevTools -> Sources -> Overrides and select a new folder for overrides, I get the prompt "DevTOols requests full access to [path...]". I click Allow, and then nothing happens. I do not have this issue with...

Last updated: Sep 19, 2024 09:07AM UTC | 6 Agent replies | 7 Community replies | Bug Reports

When I use the "show response in browser" the url does not work

Hi When I use this feature I receive a message : Unknown host : burpsuite the url is like "burpsuite:/repeat/3/epmnkg....." Would you please help me about this ? Thks

Last updated: Sep 18, 2024 08:56PM UTC | 6 Agent replies | 9 Community replies | Bug Reports

Lab: Exploiting a mass assignment vulnerability doesn't allow POST reqs

Hello, When trying to solve this lab following the given solution, after sending a POST /api/checkout request, I got a 400 Bad Request Error: {"error": "Malformed URL: query only supported with GET"}. Is this...

Last updated: Sep 18, 2024 07:19PM UTC | 3 Agent replies | 4 Community replies | Bug Reports

Vertically split UI extension not fully resizable

Hi there! We are running into a new issue since 2024.7.6 where as an example, the Authorize extension right panel isn't fully resizable. It appear that the UI will not resize smaller than the right most component on the...

Last updated: Sep 18, 2024 04:27PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Freeze on Screen Lock (macOS)

Burp Suite Pro seems to lock up every time my screen lock activates. This is Ventura 13.4 running on M2 silicon with v2024.3.1.3 When resuming, the only button that works is close and then the confirm dialog shows which...

Last updated: Sep 18, 2024 10:30AM UTC | 4 Agent replies | 4 Community replies | Bug Reports

CSRF Labs are buggy not working

Currently i'm trying to solve the CSRF labs. However, it seems that these are not working properly; It seems that the system doensn't work when you "deliver exloit to user". I know for a fact that the CSRF Payload is...

Last updated: Sep 18, 2024 06:28AM UTC | 6 Agent replies | 7 Community replies | Bug Reports

Lab: CSRF vulnerability with no defenses

Hello, going through the lab https://portswigger.net/web-security/csrf/lab-no-defenses, for some reason he does not solved. https://forum.portswigger.net/thread/lab-csrf-vulnerability-with-no-defenses-35a98ebd I had...

Last updated: Sep 18, 2024 03:51AM UTC | 5 Agent replies | 5 Community replies | Bug Reports

the Dashoard tab wasn't visible

the Dashoard tab wasn't visible for projects with crawl tasks started。

Last updated: Sep 17, 2024 01:30PM UTC | 6 Agent replies | 5 Community replies | Bug Reports

Burp Collaborator Problem

I have installed burpsuite and the cerification tested it and all works fine, I can intercept the HTTP&HTTPS requests, but the collaborator doesn't works. I have tried to made a normal get request from the browser to the...

Last updated: Sep 17, 2024 12:25PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Solution not functional: "Lab: HTTP request smuggling, confirming a TE.CL vulnerability via differential responses"

The solution provided in the following lab is not functioning correctly: "Lab: HTTP request smuggling, confirming a TE.CL vulnerability via differential responses" After setting the correct host header and ensuring that...

Last updated: Sep 17, 2024 11:20AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

'Stream failed to close correctly' when trying to load one lab

Accidentally broke one of the labs - https://portswigger.net/web-security/csrf/bypassing-samesite-restrictions/lab-samesite-strict-bypass-via-cookie-refresh steps to reproduce: - open burpsuite chromium browser - copy...

Last updated: Sep 17, 2024 08:39AM UTC | 4 Agent replies | 8 Community replies | Bug Reports

memory leak issues with Burp Suite Pro?

My company uses Burp Suite Pro to scan a number of websites, some of these we scan roughly quarterly. Our systems team manages the updates to Burp Suite Pro on a monthly basis, so we're not necessarily always using the very...

Last updated: Sep 16, 2024 07:20PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

File Upload Lab not working

Hello, it seems to me that the first lab (remote code execution via web shell upload) is not working correctly. I managed to print the contents of /home/carlos/secret but when I submit it says wrong solution

Last updated: Sep 14, 2024 06:07PM UTC | 2 Agent replies | 4 Community replies | Bug Reports

Running BurpSuiteCE on Parrot 6.1

Hi there, I've just installed Parrot OS on my macBook (UTM). Everything has been updated, however I cannot run Burpsuite. I get the following message: java.lang.UnsupportedClassVersionError: burp/StartBurp has been...

Last updated: Sep 13, 2024 08:39PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Shortcut Keys don't work

Hi, The shortcut keys (e.g. ctrl-C, ctrl-v) don't work in the new releases. Please fix. Thanks, Carl

Last updated: Sep 13, 2024 02:00PM UTC | 4 Agent replies | 7 Community replies | Bug Reports

Cannot re-disable logging out-of-scope items to the history

Hi, when I created new project, caught several requests and added the selected into scope, I was offered the option to disable logging out-of-scope items to the history and I confirm it. It worked and there was a warning...

Last updated: Sep 12, 2024 02:13PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

getRequest() and getResponse() methods not called in the new Intercept interface

Hi, I noticed that with the new Proxy Intercept interface, when you intercept a request/response, open a custom tab (e.g. the one in your examples...

Last updated: Sep 12, 2024 01:29PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Cannot update Burp

Hi I'm trying to update my Burp to version v2024_7_5. Usually it wad done automatically by Burp. This time it didn't work. I tried to do it manually by download file from portswigger and exec installer. It didn't work...

Last updated: Sep 12, 2024 09:57AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Page 6 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image