Burp Suite User Forum

Create new post

Auditing not calling doActiveScan(...) method via Extensibility API

Hi folks, I am currently trying to learn the Burp Extensibility API using this example (in Java); https://github.com/PortSwigger/example-scanner-checks and getting stuck with something. With latest Beta version of...

Last updated: Mar 15, 2019 03:28PM UTC | 4 Agent replies | 4 Community replies | Burp Extensions

SAML Raider "failureInInitialization" with BurpSuite 2.0.16 beta

Normally, the SAML Raider extension will populate a SAML Raider tab when you select a SAML request in the HTTP History. Now, instead of populating the tab, it simply says "failureInInitialization". Awesome. I'd attach a...

Last updated: Mar 08, 2019 02:07PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp suite render

Burp render

Last updated: Feb 25, 2019 10:13AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp 2.x: Create authenticated crawl from extension

Hi Portswigger Support! I'm interested in using an extension (in headless mode) to spawn an authenticated crawl while using the 2.x versions of Burp Suite Professional. In the 1.x versions, I would have done this by...

Last updated: Feb 25, 2019 08:30AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Extender Not Displaying Plugins / Can't Refresh

I am behind a corporate proxy environment using Ubuntu. Using the corporate proxy settings I am able to use Firefox to view websites as expected so Burpsuite should be able to display the BApp Store list under the Extender...

Last updated: Feb 11, 2019 10:02AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp scanner insertion point custom encoding

I'm trying to create an extension for scanner to specify multiple insertion points and also do some custom encoding on the payload from scanner. I'm attempting to use the following example along with the documentation to...

Last updated: Jan 30, 2019 10:38AM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

SQLiPy fails to load after upgrade to v2.0.14beta

After upgrading to BurpSuite v2.0.13beta the SQLiPY extension fails to load with the following error: ImportError: signal module requires sun.misc.Signal, which is not available on this platform After rolling back to...

Last updated: Jan 28, 2019 11:44AM UTC | 1 Agent replies | 4 Community replies | Burp Extensions

Handle IInterceptedProxyMessage BEFORE it's sent to the server?

This is my first attempt at writing an extension. I would like to intercept certain requests, inspect them, and handle SOME of them BEFORE they are sent to the remote server. In other words, for certain requests, I would...

Last updated: Jan 23, 2019 04:11PM UTC | 1 Agent replies | 2 Community replies | Burp Extensions

Scope manipulation API

Methods IBurpExtenderCallbacks.{includeIn,excludeFrom}Scope make it possible to add/remove a specific URL to/from the scope. Is there a way to use these or any other API call to perform actions like those available on the...

Last updated: Jan 22, 2019 10:37AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

Retire.js not working

Hi, The retire.js extension in Burp Suite Pro is not working. I do not see any feedback during passive scanning in either the "Target>Issue" or "Scanner>Issue activity" tabs. The firefox Retire.js plugin does show issues...

Last updated: Jan 15, 2019 12:22PM UTC | 4 Agent replies | 4 Community replies | Burp Extensions

Access command line through Burp extension

As per the subject, I was wondering if it is possible to access the command line (either windows or linux) through a Burp extension.

Last updated: Jan 09, 2019 08:46AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

??????????????????? $399.00 USD ??? PortSwigger Ltd (mail@portswigger.net)

08 ?.?. 2019 01:09:36 GMT+07:00 ID ???????????: 9FC40466TM976523J ????????? ??? ayut intasut ??????????????????? $399.00 USD ??? PortSwigger...

Last updated: Jan 08, 2019 09:53AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Highlighting in IMessageEditor

Hello, I am trying to create an extension in which you can highlight single or multiple lines of text in the request or response tabs. I am having an issue when you add a “Graphic” to the IMessageEditor text area that it...

Last updated: Jan 03, 2019 07:57AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Custom payload processor / generator

My intruder scenario is brute forcing uids that are calculated based date. Current intruder has date payload, that is superb for the job. Now i would like to process these dates with my custom extension that formes uid...

Last updated: Nov 21, 2018 04:53PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Odd inconstancy in extension behaviour

Hello, I wrote an extension that fails for one of my user throwing an exception: --- Traceback (most recent call last): File "E:\BurpSuite Settings and Extensions\Extenders\OurExtensions\Radar\main.py", line 220, in...

Last updated: Nov 13, 2018 11:27AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

IExtensionHelpers.urlDecode() not handling UTF-8

I have an input string which contains an ENDASH encoded using UTF-8 as: %E2%80%93 When I decode that in my extension with IExtensionHelpers.urlDecode(String input) I get: â?? However, the Java...

Last updated: Nov 06, 2018 03:31PM UTC | 4 Agent replies | 3 Community replies | Burp Extensions

Issues with burp scanner

For one of my scan, I noticed that the scan threads request/response doesn't look like a actual captured request/response which were captured while crawling the application, Cookie part was removed from the requests for most...

Last updated: Nov 05, 2018 10:11AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Saving HttpRequestResponse to file

I noticed that there's a method called saveBuffersToTempFiles() that says that it allows saving of HttpRequestResponse objects to a file. Is there anymore information on how to use this? I haven't been able to successfully...

Last updated: Nov 01, 2018 10:47AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

Exporting scan reports using carbonator

Hi Guys, I have pro license for burp and I am using carbonator to automate my scan on windows. But as soon as the scan finishes, burp shuts down and I am unable to export the reports of scanner. Could you guys please...

Last updated: Oct 17, 2018 04:09PM UTC | 5 Agent replies | 5 Community replies | Burp Extensions

Burp API Javadoc not accessible

I noticed that the javadoc for the Burp API is no longer accessible. Was this on purpose for the 2.0 beta? https://portswigger.net/burp/extender/api/

Last updated: Oct 15, 2018 07:07AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Page 36 of 48

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image