The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Sending Request using Montoya API

Hi Guys, Sending requests using the Montoya API based on examples is to use the following : ``` api.http().sendRequest(request2Send) ``` However, when I attempted to send a request, I get the following error...

Last updated: Jan 08, 2024 03:25PM UTC | 3 Agent replies | 4 Community replies | Burp Extensions

missing HttpParameterType PATH

Hello, Why is there no PATH HttpParameterType in the montoya API? Is is meant to be included in the URL HttpParameterType?

Last updated: Jan 08, 2024 03:17PM UTC | 4 Agent replies | 3 Community replies | Burp Extensions

Unable to access labs, getting 404 Not Found

Today, I am unable to access labs through burpsuit proxy. Yesterday, I was able to access it without any issues. I tried with chrome and mozilla firefox, Both showing 404-Not Found responses for all labs. My Mozilla Firefox...

Last updated: Jan 04, 2024 10:37AM UTC | 4 Agent replies | 3 Community replies | Burp Extensions

Montoya API Documentation is not inline with the Montoya test extension

Dear all, I am looking to the Montoya test extension from here:...

Last updated: Dec 22, 2023 01:45PM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Param Miner Rate Limit

Is there a way to rate limit the Param Miner extension when it is installed in Burp Community? You cannot use the Distribute Damage extension for this purpose as it cannot be installed in Burp Community.

Last updated: Dec 22, 2023 01:15PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

I cannot install Hackvertor

I am doing this lab SQL injection with filter bypass via XML encoding. You recommend to install Hackvertor. I cannot install Hackvertor. It says installing and it stays in grey. Please help. Are there another...

Last updated: Dec 14, 2023 11:37AM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

Want to View Requests and Responses Simultaneously in Intruder

I've managed to view both requests and responses simultaneously using the following code, but it becomes cumbersome when redirects occur, as it doesn't display the initial request and response. Is it possible to develop an...

Last updated: Dec 12, 2023 11:39AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Ignore Macro for certain scan

I am currently working on developing a Python extension for active scanning. This extension has the ability to perform various types of scans, and as long as the user has configured macros, there are no issues with the...

Last updated: Dec 11, 2023 11:40AM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

Which extensions to use?

I want to perform basic vapt scanning on a domain or subdomains. So which are all the extensions that i can use for basic scanning.

Last updated: Dec 08, 2023 10:12AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Dynamically inserting client certificate

I've created a python extension to scan replies from a certain url for a certificate, and then save it to disk and run a command to convert it to pfx. This all works, I can then manually load it into the Project Options ->...

Last updated: Dec 05, 2023 10:23AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Cannot clean up configuration

Hi - I added the reshaper BApp, played around with it, and added a Rule for WebSockets containing an "unacceptable code point '–' (0x96)". Now on Loading the extension again (auto on startup or manually) I get an Error...

Last updated: Nov 24, 2023 09:54AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Extension driven passive audit

I have recently started seeing "Extension driven passive audit" automatically get created while I am testing. I checked the forums and prior release notes and didn't see any good answers to my questions. So here they...

Last updated: Nov 22, 2023 10:00AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

gradlew error - HTTP Request Smuggler

Hi portswigger, When i run this command(gradlew.bat build fatjar or ./gradlew build fatjar), I get this erorr: ``` C:\Users\xxx\Desktop\http-request-smuggler-75a40815a944391bfbefe9c8b70faec1fae3ea21>gradlew.bat build...

Last updated: Nov 21, 2023 01:44PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Calling Logger through Montoya?

Hey there, I'm trying to create an extension which has a listener attached to the Burp Logger. Every time new requests/responses are logged, the extension will look through the new requests/responses and save the...

Last updated: Nov 20, 2023 01:18PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Montaya extension examples

For the old API (weiner) there was example in java, python and ruby. For the new montaya API there are only examples in java. Please add examples in python and ruby too.

Last updated: Nov 20, 2023 11:00AM UTC | 2 Agent replies | 2 Community replies | Burp Extensions

Python Extension Loading Errors

I'm encountering this issue with all Python extensions from the BApp store and my personal extensions. This started to happen after a burp update at some point. I'm currently running 2023.10.3.4 but this started to happen...

Last updated: Nov 17, 2023 04:08PM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

HTTP Request Smuggler CLI

Hello portswigger, I want to use the HTTP Request Smuggler extender as cli, how can I do it? Regards.

Last updated: Nov 17, 2023 10:09AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Multiple IMessageEditorTab

I am working on creating two IMessageEditorTabs, one for requests and the other for responses. I know that I could use just one IMessageEditorTab and check whether the message is a request or response inside it. However, I...

Last updated: Nov 16, 2023 10:06AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Log4jShell scanner removed? Does Active scan++ supports Log4jshell?

Hi, Any reason why Log4jShell scanner extension is removed from BApp Store? Also, since Log4jShell scanner removed, does for all the below variants are supported by Active scan++ Feature Log4Shell scanner (this...

Last updated: Nov 16, 2023 07:52AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

I can't install Highlighter and Extractor extension

Hi! I have a problem with the "Highlighter and Extractor" extension, it happens that when I want to install it from the BApp Store or manually, it gives me the following error: java.lang.Exception: Extension class is not...

Last updated: Nov 08, 2023 02:51PM UTC | 3 Agent replies | 5 Community replies | Burp Extensions

Page 5 of 50

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image