The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

burp community-failed to connect to website.com:443

Hi, I'm trying to connect to website using burp chromium browser. But most of the time, the loading end by an error screen saying "failed to connect to website.com:443" I searched but didn't fought any awnser that helped...

Last updated: Sep 12, 2024 08:23AM UTC | 4 Agent replies | 4 Community replies | Bug Reports

Burp would change hex values of non-printable characters in binary files in POST request (repeater/intercept)

Hi, I'm on version v2024.7.5 I encountered bug in intercept and repeater. When editing POST request that has attached in body binary file like xls. After modyfing as little as one character in "pretty" and "raw" tab in...

Last updated: Sep 12, 2024 08:17AM UTC | 4 Agent replies | 3 Community replies | Bug Reports

Send to Intruder inserts character markers at incorrect positions when executed from the GraphQL message editor tab

Bug overview: Intruder markers are added to the wrong character positions when the "Send to Intruder" action is executed while selecting text in the new GraphQL message editor tab. The Intruder markers appear to be inserted...

Last updated: Sep 11, 2024 02:19PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Issue with Burp Suite Version 2024.7.5 - Crashing During RDP Sessions

We have encountered an issue with Burp Suite Professional version 2024.7.5 where the application crashes while connecting through RDP. This issue significantly affects our workflow, as we heavily rely on remote sessions for...

Last updated: Sep 11, 2024 11:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Nothing happens when I click on the "Open browser" button

Hello all, I use Ubuntu 24.04 LTS (with gnome 3). I have downloaded the last version (30 august 2024) which is burpsuite_community_linux_v2024_7_5.sh When I click on the "open browser" button, nothing...

Last updated: Sep 11, 2024 10:24AM UTC | 1 Agent replies | 3 Community replies | Bug Reports

Scanner Is it a bug? "Cross-domain Referer leakage" is reported despite no sensitive data in the "Referer" header, why?

Hi team, Need some clarifications on this scanner category "Cross-domain Referer leakage". My client needs to use this burp pro scanner feature. Burp Pro scanner reports "Cross-domain Referer leakage" even no...

Last updated: Sep 11, 2024 09:32AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Exploiting insecure output handling in LLMs not solving

seems that the lab Exploiting insecure output handling in LLMs i have also tried the sugested solution. if i ask for the review it delete my profile but is like carlos is never asking info about the l33t product.

Last updated: Sep 11, 2024 07:29AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

"Cross-domain Referer leakage" is reported despite referrerpolicy attribute

Hello, an active scan on one of our applications reports a "Cross-domain Referer leakage". Taking a look at the response tab in Burpsuite, the following snippet is highlighted: <a class="info-box" target="_blank"...

Last updated: Sep 11, 2024 01:19AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Can't start BSCP Exam

Hello, I purchased access to the BSCP exam today, I'm going through the process for the second time. I passed the initial session on the Examity portal and when I try to start the exam on the examiner's page, I see the...

Last updated: Sep 10, 2024 08:23AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

LAB Not solved

Labs are not getting in solved status even after taking the right approach or the suggested approach in the exercise. 1.Reflected XSS into a template literal with angle brackets, single, double quotes, backslash and...

Last updated: Sep 10, 2024 08:18AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab status bug

Hi team, So far, I have observed this unsloved to solved status bug. Even if you do the labs correctly, the lab doesn't gets solved. 1.Reflected XSS with some SVG markup allowed 2.Reflected XSS into a JavaScript...

Last updated: Sep 10, 2024 08:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

2024.7.5, Montoya API, Extensions, Custom Editor Tab, Modified Requests Not Forwarded

I have received a bug report about our SAMLRaider extension that the modified requests are not being forwarded correctly. This problem occurs with the new BurpSuite version 2024.7.5. I can reproduce the bug, but I am not...

Last updated: Sep 09, 2024 04:36PM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Password found for lab "Information disclosure in version control history" can't login

Hello all, I think there is a bug on this lab : https://portswigger.net/web-security/information-disclosure/exploiting/lab-infoleak-in-version-control-history In the diff for admin.conf I have : ...

Last updated: Sep 09, 2024 03:19PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Burpsuit pro cluster bomb payload set can't add different payloads

For example, I have 2 payload sets need to be set different payloads. After I set 1st set which is filled with usernames, the 2nd set will always add the 1st set's payloads in its payload list. It should use different...

Last updated: Sep 09, 2024 11:02AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Could not start Burp: java.lang.NullPointerException: Cannot invoke "String.startsWith(String)" because "platName" is null

Hello all, I use Ubuntu 24.04 LTS (with gnome 3). I have downloaded the last version (30 august 2024) which is burpsuite_community_linux_v2024_7_5.sh First, when I try to run the installer I got : Could not...

Last updated: Sep 06, 2024 09:23AM UTC | 2 Agent replies | 3 Community replies | Bug Reports

Burp 2024.7.5 - Contents of Repeater Tab Persist Even When Repeating a Request

hi there In historical versions of burp, when a user repeats a request in the repeater, the contents of the response are cleared pending the contents of the newly created request. This enables the user to visualize when...

Last updated: Sep 06, 2024 08:43AM UTC | 3 Agent replies | 1 Community replies | Bug Reports

Issue with LAB - Routing-based SSRF

hi everyone when I change the host header with my collaborator payloads or whatever I receive this response : HTTP/2 421 Misdirected Request Content-Length: 12 Invalid host so i can't go head to solve the lab

Last updated: Sep 05, 2024 05:32PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Issue with BSCP exam.

Hello and greetings, I recently took the BSCP exam and encountered an issue where the results I received were not valid. I'm reaching out to confirm if this is the intended behavior or if there might have been a technical...

Last updated: Sep 05, 2024 01:23PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Incorrect path reported in target sitemap

Hello, I'm testing a website that uses Japanese characters in URL path and I've noticed that in some cases the discovered paths are incorrectly logged in the target sitemap in Burp. Steps to reproduce: 1) setup a...

Last updated: Sep 05, 2024 10:24AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: Exploiting exact-match cache rules for web cache deception

Hi all! Tell me, only in my “Lab: Exploiting exact-match cache rules for web cache deception” when sending an exploit to a victim, she does not switch to it. That is, the logs do not show that he is accessing it, and...

Last updated: Sep 05, 2024 06:36AM UTC | 2 Agent replies | 3 Community replies | Bug Reports

Page 7 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image