Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft
Hi, I think there is a problem with the Payload Processing module while using a Pitchfork attack. Indeed, the rules mentioned in this module are applied to all payloads and can only be defined once, which was not the case...
Hi, I am using Burp pro v2020. I will report a bug issue. I used Intruder by flowing Payloads settings; [Positions] Attack type: cluster bomb (2 payload positions) - All positions are in URL (eg. "POST...
In the previous versions of Burp CE, double-quoted strings were green. In the new version, the strings are black, and the text is hard to read. In addition, when you remove the last " character from the json request, the...
I found a bug impacting streamed responses. How to reproduce: - access this (streamed) URL in Repeater https://139.162.22.237/mutillidae/index.php?page=phpinfo.php - Burp will convert from "stream" to "normal" (add a...
Windows 10 x64 Java - 15.0.1 Burp Suite Professional v2020.11.3 -- Add a URL to streaming response(Project options->HTTP->Streaming Response->Add), and request this URL in Repeater. Cannot see the response boby is...
I hope this is the right category (it might not be a bug). I'm having a problem when using a maximized Burp Suite Professional window on MacOS. After clicking filter, it switches to entirely new screen just to show the...
Dear Port Swigger team When I want to download a community edition burp suite to my Windows 10 computer, I cannot download it when I apply the Turkish translation option to the page.For your information. I don't know much of...
Hello, I've been trying to use the newer burp but so far I'm having great trouble making it actually perform its job effectively due to scans rarely finishing and having to frequently be "unstuck". The pattern at the...
Hello. I have a free trial version of Burp Suite Enterprise edition, but license doesn't work. I activate license 4 days ago.
Thanks for the great web security academy. In this lab: https://portswigger.net/web-security/cross-site-scripting/contexts/lab-some-svg-markup-allowed with an xss payload of alert(1) they lab didn't get marked as...
Hello Burp suite I have some problems about setting Korean font in macos When I do web pen testing, a homepage has Korean language. Therefore I need to change Korean font in the Burp suite MISC option. But there is...
The license key on uploading is giving issue
Hi, I wanted to learn and train my skills in BurpSuite and was happy to find the Burp Academy. Unfortunately I am not able to access any of the labs as all I get is a 404 response in both Firefox and Chromium on a Kali...
I cannot access Web Academy CSRF lab. error: Not Found The requested item was not found. We apologize for the inconvenience.
Can someone please help me? I am have the updated version of BurpSuite Community, but I am unable to use BurpSuite's browser nor am I able to use my own. I have run a healthcheck and this is the result: Embedded...
Kali-Linux-2020.4 BareMetal SSD dedicated hard-drive install. No dual boot. Pre-installed burpsuite community edition fails to launch GUI but process IS confirmed running in task manager.
Hello Team, I had requested for trial version; the license I downloaded from the portal is invalid. Account: mshankarpani@quinstreet.com Thanks, Madhu
Hi, I think that I found a flaw on https://portswigger.net/web-security/web-cache-poisoning/exploiting-implementation-flaws/lab-web-cache-poisoning-cache-key-injection lab, you can solve the lab just by adding Pragma:...
Hello. I was doing a Burp Scan the other day and the report gave me an "External Service Interaction (DNS)" finding. The collaborator payload was submitted in the SSL SNI and the HTTP Host header. I checked with Logger++...
Page 94 of 156
Your source for help and advice on all things Burp-related.