Burp Suite User Forum
Hi there, In my extension, I am making requests with makeHttpRequest() method. And both request and response are visible in Logger. The problem is this request requires that the request body is encoded with RSA + cert...
Hello, I noticed that during a scan, one of the loaded extensions is putting the full URL in the request line. For example, the original request has this request line: "GET /robots.txt HTTP/2" in a request to...
Hello! I am writing an extension that can move requests from Postman collection to Site map using Python. To move requests python script parse Postman collection JSON file. My script works correctly, but I stacked with a...
Hey, I am looking to build upon Burp's insertion points for intruder. Is there a way to get the default insertion points for a request? I thought it might be markers() but this returns an empty list for a multi-parameter...
Hi There, I am trying to run burp headless mode to get the scan automation inside my CLI without opening Burp Application, but I am unable to run this with headless mode. Could you please help me with this and get this...
Hi, is there an easy way to cast org.springframework.http.HttpRequest to Montoya-API HttpRequest? Thank you
I am trying to create a BURP extension which takes current request and grabs path from it and add some custom_path and create http request using headers from currentRequest. The paths are a total of 200 My problem is that...
Hi there, I am trying to send a request with the method sendRequest(); String body = "GET /vdp/helloworld HTTP/1.1\n" + "Host: sandbox.api.visa.com\n" + ...
Hi there, If I need to make a request which requires multiple certificates (.p12, public .pem & private .pem). Which method/Interface i can use to send these requests? And is there some example code on how to make...
Hi there, is there a way to log requests made by extension in the History tab? My use case is that when we make requests via our extension, we would like to be able to send this request to the Repeater. I know it's...
Hello everyone, I'm working on the practice exam for the Burp Suite certification. As many of you may know, the last stage involved an insecure java deserialization. Since there is no contextual clues as to what gadget...
Hi, Can Montoya persistence be used to load a list of extensions from the Burp extension store or even custom extensions (given the .jar location)? The line in the release notes "Import extension data from another project...
Hi there, I'm developing a new extension using the Montoya API. I'm planning to register a new `ContextMenuItemsProvider` which provides a way to insert a string at a certain position into the request body in the...
Hi team, I like know how to integrate burp suite pro with selenium automation for to perform active scan and spider. i have successfully done proxy the https with selenium scripts but I'm not able to trigger spider or...
I want free trail version of burp suite professional but haven't received activation email on the following mail (farooq.umer@edufi.tech). Kindly look into this asap
Hi there! I am testing a brute force attack on a software. For the Anti-Csrf token I am trying to use grep extract => but it is failing and error of failed to fetch response is coming and its not like the response isn't...
I want a callback to my extension when any Scan is completed. For example, I want to send a notification through SNS etc. when the scan is completed. Is it possible to get the flag when the scan is completed? I saw...
I want to build an extension for Burp with python. I downloaded Jython and set Pycharm to use it as an interpreter but it doesn't recongnize java or javax when importing them and I can't find a way to get it to work. Can...
I am struggling to open BApp. I have downloaded the app but it won't open.
I am getting error as "Burp did not start properly last time. do you want to start it without loading extensions" and then burp screen gets freeze.
Page 11 of 48
Your source for help and advice on all things Burp-related.