The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

decoding/encoding http request

Hello, I want to use following request to send it to the server!. /**********************************************/ POST /vaadin_vulnerabilities/UIDL/?v-uiId=2 HTTP/1.1 Host: localhost:8080 User-Agent: Mozilla/5.0...

Last updated: Oct 20, 2016 08:01AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Issues running any Ruby dependent extension

I'm trying to run Buby on my MacBook Pro Burp Pro. When trying to load the extension, I get the following error: LoadError: no such file to load -- pp require at org/jruby/RubyKernel.java:1040 (root) at...

Last updated: Oct 19, 2016 06:04PM UTC | 1 Agent replies | 2 Community replies | Burp Extensions

TEst

&#x27;><svg/onload=alert(9)>

Last updated: Oct 19, 2016 06:03PM UTC | 0 Agent replies | 0 Community replies | Burp Extensions

Intruder/Payload pattern-matching algorithms

Hello everyone, I have to "copy" some of the functionalities within burp for writing my own extension. This includes the "Intruder" tab aswell. To be honest the "Intruder" tab in burp is really really amazing. It...

Last updated: Oct 19, 2016 08:26AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

IHttpRequestResponse - setRequest(byte[] message)

I am currently working on writing my own extension for burp suite: I get an exception when using the "setRequest(byte[] message)"from the IHttpRequestResponse interface, which looks...

Last updated: Oct 17, 2016 09:03AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Debug Java-Project

Hello, I am writing my own extension for burp and I was wondering if someone could tell me, if there is a way I can use the debug mode in my eclipse project to detect bugs etc.? The current situation is that whenever...

Last updated: Oct 13, 2016 10:08AM UTC | 1 Agent replies | 2 Community replies | Burp Extensions

Problem with IScanIssue getHttpMessages()

I have users reporting issues with an extension that was working fine in 1.6x but is having a problem in 1.7.04 (I did not try with any earlier 1.7x release). The root cause is that the IScanIssue getHttpMessages() method...

Last updated: Oct 10, 2016 06:53PM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

Modifying message

Hi, I,m writing an extension which decrypt requests and responses and send it to Proxy-Intercept tab. So, I want to modify this message,ecrypt it and send forward, but message what is modified will not changed. In example...

Last updated: Oct 05, 2016 04:58AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

Burp scanner: how to add support for csrf tokens

I'm having an issue with the Burp Scanner: when anti-csrf tokens are present, it seems the scanner cannot handle it and it faild to perform active/passive scans. Would it be possible through Burp Extension capabilities to...

Last updated: Oct 03, 2016 02:22PM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

Burp Suite 1.7 and carbonator

Hi, we were using Burp Suite Pro with Carbonator extension for a long before and it was working well as we have automated scans by launching it from command line. From version 1.7 we had to make some changes in script,...

Last updated: Sep 27, 2016 02:47PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

applyMarker in Ruby - java Class Cast Exception

I am using Ruby to develop an extender, that do passive scan for a particular string in response. Everything is working fine apart from applyMarkers. When applyMarkers method is called I am receive the below error. Any Idea...

Last updated: Sep 22, 2016 07:55PM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

makeHttpRequest (timeout)

Hi, I am creating a Burp extension which is using the makeHttpRequest functionality in order to send some requests, but I would like to assign a maximum timeout to these request. Some of them could not have a...

Last updated: Sep 21, 2016 03:08PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Potentially misconfigured headers from extension "Header Analyzer"

The "Header Analyzer" extension reports the following issue: Potentially misconfigured headers: Header name: x-xss-protection. Header value: 1; mode=block My response contains this header: X-XSS-Protection: 1;...

Last updated: Sep 14, 2016 01:07PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Why Burp asks to activate license when starting by cmd.exe

Hi all, I met a problem with Burp. I developed a java extension to launch burp in cmd.exe. I wrote a .bat file and call it by Java Runtime. It asks me to activate the license again. If I open the .bat file directly, it...

Last updated: Sep 13, 2016 07:38AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Forcing Burp to open w/ scanner unpaused?

Is is possible to force Burp to open in a state which scans are forcibly unpaused? I'm working on a project where we call doActiveScans() to a single entry from getProxyHistory(), and upon clicking on the "Scanner" tab, the...

Last updated: Sep 07, 2016 08:28AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

How to enable SQLiPy on Burp

I have added SQLiPy on Burp and I can see the tab too however I am not sure what to be added in the proxy and port to start it. Even when I tried adding it with my PC's proxy nothing is happening when I click on Start...

Last updated: Aug 24, 2016 09:08AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Stop scanning form API call

Hi, Is there any API to stop scanning and start scanning. I want to stop scanning when session is invalidated and resume on proper sessions. How can I achieve this. Regards, Sid

Last updated: Aug 24, 2016 08:48AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Modifying message before intercepting

Hi, I'm writing an extension which uses processProxyMessage() to modify the targets and bodies of various requests in various ways. For certain requests, I use message.setInterceptAction(ACTION_DO_INTERCEPT) to have the...

Last updated: Aug 22, 2016 03:38PM UTC | 2 Agent replies | 0 Community replies | Burp Extensions

SQLPy Extension

Hi I cannot find the START SCAN button on the new version of SQLPy extension. Please help.

Last updated: Aug 22, 2016 09:24AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Spider treating active scan URLs with injected parameter queries as new urls to spider.

I built an extension that successfully spiders the application, but I have a problem where when active scanning starts in earnest, eventually it starts adding injected URLs into the scanning scope, thus duplicated the amount...

Last updated: Aug 17, 2016 11:16AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Page 46 of 51

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image