Burp Suite User Forum

Login to post

Turbo Intruder

Hello team, I'm practicing the upload file vulnerabilities labs now and i tried to solve it with introduce solution but i still getting 400 errors back at the turbo intruder and can't achieve the secret. The lab:"Web...

Last updated: Dec 21, 2021 09:17AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Manual Install of Burp Extension

Hi, I hope I didn't miss it anywhere on the website, but I couldn't find how to install a local Jython extension in Burp through the Manual Install-button in the BApp Store tab. The extension runs fine in...

Last updated: Dec 14, 2021 06:35AM UTC | 7 Agent replies | 7 Community replies | Burp Extensions

Add extension to active scan

Hi everyone, Can I add/edit an active scan payloads list? Can I add a custom extension to the active scan extension so my custom extension will be triggered during the active scan as well?

Last updated: Dec 13, 2021 10:49AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

RSS feed for burp extensions

Just like the burp versions, is there an RSS feed for newly added extensions in the bapp store? Or should one write a custom parser on it?

Last updated: Dec 13, 2021 09:21AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

HTTP Request Smuggle false positives

Hello, I've learned a lot on this topic by resolving every lab, but now I have been trying to find them in the real world and when I use this extension many times it finds at possible CL.TE or TE.CL and it always says...

Last updated: Dec 10, 2021 11:55PM UTC | 0 Agent replies | 0 Community replies | Burp Extensions

Extension is not following redirects.

Hello Team, Hope you guys are doing well. I 'm currently writing an extension for my burp suite but i 'm facing an issue related to following redirects properly in extension code. I 'm using Jython as development, and...

Last updated: Dec 08, 2021 06:37AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

Extensions Load Error

Hello, While installing java or ruby related plugins, plugins with python do not load and give an error message. I tried to download from the bapp store is not installed. Burp Suite Professional 2021.10.3 OS:...

Last updated: Dec 07, 2021 09:46AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

How to invoke a burp enterprise scan with extension from command line / jenkins CICD

Hello, Our organization has a burpsuite enterprise license. We are trying to invoke burp enterprise site (with custom configuration and extension) from jenkins or from REST API - POST screen. I have created a burp...

Last updated: Dec 06, 2021 09:13AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Why do my built in lists in Burp have {Base} in the payload and how do I use them?

So, in Intruder if I load certain built in payload lists (like the SQLi one), many of the requests have an entry like "{Base}' or 1=1--", however then the request is sent to the server like: GET /example.php?id=123{Base}' or...

Last updated: Nov 25, 2021 09:01AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

ip rotate

i have installed the extension IP rotate and require fields. further provided required access key and secret key from aws services. yesterday it was functioning well. but now it is not getting enabled only and at the same...

Last updated: Nov 25, 2021 08:27AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Issue with ATOR Loading an Access Token

I seem to be having an issue with the way that ATOR is pulling an access token from a Request. I have dug into the issue and it appears to not be properly pulling the token and replacing it in my requests. I tried a few...

Last updated: Nov 18, 2021 07:43AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Errors when installing python/jython extensions

When installing a python extension such as Authorize I'm getting this error. Traceback (most recent call last): File "/home/myhome/.BurpSuite/bapps/f9bbac8c4acf4aefa4d7dc92a991af2f/Autorize.py", line 9, in <module> ...

Last updated: Nov 16, 2021 09:57AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

burpsuite

hello, am using MacBook pro M1 and i was able to download Kali linux but the burpsuite is not found on the virtual machine. any help?

Last updated: Nov 16, 2021 09:38AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Add burp extension manually

I want to install https://github.com/intruder-io/param-miner this extension manually,how can I make it as a jar file.Thanks in advance

Last updated: Nov 15, 2021 10:07AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

How to update the Multipart Attributes parameter correctly?

Dear support, I'm working on an extension that modifies the multipart attributes of a file that is uploaded via a multipart request. See the example request below: POST /doUpload.action HTTP/1.1 Host:...

Last updated: Nov 10, 2021 01:14PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

How to make requests from custom scan checks appear in the Logger tab of the task

Hello, After performing an active scan, I usually go into Dashboard >> "View Details" of the task >> Logger tab to see the requests that were done and how the server responded to them. However I noticed that requests...

Last updated: Nov 09, 2021 02:04PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

what is the positive or false positive? Or do you need to solve the problem? Cookie manipulation (DOM-based)

I have a question, would you like to know false positive or positive? Or do you need to fix? HTTP/1.1 200 OK Date: Mon, 13 Sep 2021 14:03:31 GMT Server: Apache Strict-Transport-Security: max-age=31536000;...

Last updated: Nov 04, 2021 01:00PM UTC | 0 Agent replies | 0 Community replies | Burp Extensions

intrusive or not

Hi, How do I know if an extension I'm interested in, is intrusive or not. My goal for the time being is to run scan that will not harm the location/DB/code that I'm scanning

Last updated: Nov 03, 2021 10:40AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

iprotate extensions

hello all i have configured jython and I used my credentials in IP rotate and still not able to rotate ips my IP is not rotating.. Please help

Last updated: Nov 01, 2021 11:15AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Error in python burp extensions

Hello everybody, I have this error when try to enable python burp extensions : " java.lang.Exception: Failed to open Jython JAR file at burp.a8h.<init>(Unknown Source) at burp.dhy.a(Unknown Source) at...

Last updated: Nov 01, 2021 09:48AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Page 5 of 33

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image