The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Upgrade from 2021_8_3 to 2021_8_4 failing

Hi there, When I try to upgrade from 2021_8_3 to 2021_8_4 via the in-app upgrade button (where it asks you to restart), it fails silently. When I download the installer and try to reinstall from the command line I get...

Last updated: Oct 11, 2021 11:08PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

academy site bug

Hello. I found a bug in the title below on the academy site. "Exploiting cross-site scripting to steal cookies" procedure: 1.Click "View post" in Festivals 2.Enter the following payload in "Comment" and click...

Last updated: Oct 11, 2021 03:00PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

burp automatically add entries on tls failure NOT WORKING

I'm using Burp community edition 2021.8.4 the .jar version The proxy feature to automatically add entries on tls failure is not working... To check that wasn't my mistake I downloaded older version of burp...

Last updated: Oct 11, 2021 12:24PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Crawler Problem

Why Burp Suite shows different result between Crawl & Audit and (Doing Crawl and Audit at Target Site map tab after)? I cannot see the difference on crawl, but it shows different number of bugs.

Last updated: Oct 11, 2021 09:48AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Recorded login sequence issues

Hello, I am attempting to create and use a recorded login sequence in a scan in my enterprise trial edition burp suite. I recorded the record sequence using the chrome extension and added it as the login sequence as...

Last updated: Oct 11, 2021 08:29AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Failed to create Burp project: Cannot invoke burp.gqv.aF

Burp Suite Error on Start up: An error occurred when starting a project with the selected options. Failed to create Burp project: Cannot invoke burp.gqv.aF() because the return value of burp.bvz.aQ() is null

Last updated: Oct 11, 2021 08:17AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Failed to connect to port 8090

I have burp community version that come pre install on Kali Linux .I have installed Kali on 1st of July till 8 October it was working well now when i used to do it is showing failed to connect port 8090 i have tried...

Last updated: Oct 11, 2021 07:46AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

8.4 Malformed reply from SOCKS server

I updated from 8.3 to 8.4 in Burp Professional and get a Malformed Reply from SOCKS Server trying to load a page

Last updated: Oct 08, 2021 01:59PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Academy Leaning Material minor mistake on "Finding HTTP request smuggling vulnerabilities" page.

Not sure if this is the correct place to raise this but I believe there is a small issue with the learning material on this page - https://portswigger.net/web-security/request-smuggling/finding. Specifically the request...

Last updated: Oct 08, 2021 12:52AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

cache server

Hello, Cache server don't reflect any hit messages, even when changing the headers as indicated by the lab solution I don't receive any hits, I think the bug is related to cache server. Thank you for fixing the...

Last updated: Oct 07, 2021 11:25PM UTC | 2 Agent replies | 2 Community replies | Bug Reports

One of the SQL injection lab, is not working with the solution.

Lab: https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft this lab is not working, i tried a lot and then i tried the solutions given by portswigger but...

Last updated: Oct 07, 2021 05:42PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Scanning Time - Too long

Hi, I purchased the Pro version and have the following specifications on my VM. My VM has 8192MB of memory, 40,9GB hard drive. I have checked your article, but it doesn't help. The issue is that scanning takes a very...

Last updated: Oct 06, 2021 08:11AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

gettin error code : SSL_ERROR_RX_RECORD_TOO_LONG

iam using firefox ,i changed proxy and imported CA certificate. when i try to intercept iam getting error message Secure Connection Failed An error occurred during a connection to www.google.com. SSL received a record...

Last updated: Oct 06, 2021 06:20AM UTC | 11 Agent replies | 34 Community replies | Bug Reports

Issue with Web Security Academy

Hi there, I hope you are doing well. I am trying to complete a lab called "Lab: Web cache poisoning with an unkeyed header" and I am doing fully what I am being requested. My steps are: GET /...

Last updated: Oct 05, 2021 01:26PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

OMIGOD Vulnerability

There are 4 vulnerabilities impacting Linux servers. These go by OMIGOD. CVE-2021-38647 – Unauthenticated RCE as root (Severity: 9.8) CVE-2021-38648 – Privilege Escalation vulnerability (Severity: 7.8) CVE-2021-38645 –...

Last updated: Oct 05, 2021 01:15PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE

Description: On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active STEPS TO REPRODUCE: 1. Log in to Browser A and make...

Last updated: Oct 05, 2021 07:42AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

3 Days Now, No License

Hi, Purchased a license 3 days ago. I've sent emails to both "office" and "hello," with no response. Please advise. Thanks

Last updated: Oct 05, 2021 07:36AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

SESSION DOES NOT EXPIRE AFTER PASSWORD CHANGE

Description: On changing password both session using which user changes password and old sessions in any other browser or device does not expire and remains active STEPS TO REPRODUCE: 1. Log in to Browser A and make...

Last updated: Oct 04, 2021 04:33PM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Reflected XSs

The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts. POC : Step 1: Open the website : https://portswigger-labs.net/ and insert payload...

Last updated: Oct 04, 2021 12:39PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Reset license key from my account page via web site

Hi, How do i can reset my license key from my account page via web site? I lost access to my HDD and I forgot to press "Remove Burp license key" on a old HDD and now can not install Burp on a new machine. Please any...

Last updated: Oct 04, 2021 08:16AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Page 77 of 156

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image