Burp Suite User Forum

Create new post

Burp File Size - Extension data vs Persistence

Hi, Im having some issues with Burp file sizes due to extensions, but I'm confused as to the cause. I have an extension I created that is causing Burp files to balloon to 20x their normal size. As this extension makes...

Last updated: Jun 23, 2023 12:15PM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

Failed to download Bapp File

I encountered an issue while attempting to install a plugin from the BApp store as the Bapp File failed to download. Interestingly, when I utilize the URL "https://portswigger-cdn.net/bappstore" in my personal browsers such...

Last updated: Jun 23, 2023 10:38AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Importing external JFreeChart library - ClassNotFoundException

Hi, I'm developing a Burp extension in Montoya, and I'm using the external JFreeChart library to implement some graphing functionality. I have added it as a dependency in the following way: In the project...

Last updated: Jun 21, 2023 08:54AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Turbo Intruder error

Hi everyone, I've just downloaded Turbo Intruder and was about to use it for the first time. I chose one of the easiest lab for this...

Last updated: Jun 21, 2023 06:54AM UTC | 5 Agent replies | 7 Community replies | Burp Extensions

Why do my built in lists in Burp have {Base} in the payload and how do I use them?

So, in Intruder if I load certain built in payload lists (like the SQLi one), many of the requests have an entry like "{Base}' or 1=1--", however then the request is sent to the server like: GET /example.php?id=123{Base}' or...

Last updated: Jun 16, 2023 01:19PM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Highlighting in the Text Editor

In newer versions of Burp, the text editor highlights the request and response. Now for extensions it would be nice to "hook" into this process or replicate it in the TextEditor. I've tried to add <html> at the start of...

Last updated: Jun 16, 2023 09:12AM UTC | 3 Agent replies | 4 Community replies | Burp Extensions

Other Extension interference

Hey, I've written an extension that analyses an app's parameters. However, I come across an issue with other extensions such as log4shell everywhere adding the query parameter "action" to every request. I've played with...

Last updated: Jun 16, 2023 08:04AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

Confirmation of payment for extension of license

Hi, I would like to inform you; we made a payment in total amount of 449,00 USD. Payment is still in process. Could you please give me contact (e-mail address) to whom I could deliver proof of made payment. Thank you in...

Last updated: Jun 15, 2023 07:33AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Burp Automation - Scanning for specific vulnerability

Dear, I want to write a burp extension in java, that will use burp scanner. Can we scan a request with specific (user defined) audit configuration in burpsuite professional. Like, extension will check if there is an id...

Last updated: Jun 14, 2023 11:04AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Manual Install of Burp Extension

Hi, I hope I didn't miss it anywhere on the website, but I couldn't find how to install a local Jython extension in Burp through the Manual Install-button in the BApp Store tab. The extension runs fine in...

Last updated: Jun 14, 2023 07:40AM UTC | 8 Agent replies | 8 Community replies | Burp Extensions

Java Deserialization Scanner

Hello, It was checked that Java Deserialization Extension is not working properly anymore. It does not provide correct results while scanning vulnerable to Insecure Deserialization web application. I hope someone can...

Last updated: Jun 12, 2023 07:59AM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Sending Request Montoya

I'm trying to send a request with the following code, but getting -1. What's wrong with this workflow? TIA! HttpRequestResponse ret =...

Last updated: Jun 07, 2023 01:00PM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Delete specific request from Burp's proxy history using my custom plugin

Hello, Is there a Burpsuite API that could be used to manipulate (or just delete) a specific request/response in the proxy history tab? Appreciate your support

Last updated: Jun 07, 2023 12:47PM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Send HTTP request to extension?

Hi, I'm writing an extension in Montoya. Is there a method for accessing the Extensions option you get from right clicking on a request in the proxy or repeater? I want to have the following workflow: right click a...

Last updated: Jun 06, 2023 08:10AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

IScanQueueItem.getIssues() not returning issues

IScanQueueItem.getStatus returns the updated Status but IScanQueueItem.getIssues() not returning any issues of completed scans. But Burp UI shows issues in portal. Am I missing anything? I'm testing with Burp pro...

Last updated: Jun 02, 2023 11:04AM UTC | 3 Agent replies | 2 Community replies | Burp Extensions

Decode Base64 Post body for Scanner

Hi team, I have a requirement wherein I want to perform active scan on requests that contain base64 encoded POST body. The entire body is base64 encoded. The body when decoded, gives JSON data. I want to write an extension...

Last updated: Jun 01, 2023 01:48PM UTC | 4 Agent replies | 3 Community replies | Burp Extensions

See modified Request in Extension

Hi there, I have two extensions, I make a request in one of the extensions in the same extension I modify the request/response in processHttpMessage method. I can see this modified request/response in Logger correctly....

Last updated: Jun 01, 2023 01:23PM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Requesting more details on security reviews executed by PortSwigger on BappStore extensions

Hello! Based on the following quoted text extracted from: https://portswigger.net/burp/documentation/desktop/extensions "We review community-created extensions for security and quality before we make them available...

Last updated: Jun 01, 2023 07:32AM UTC | 1 Agent replies | 0 Community replies | Burp Extensions

Get Websocket Server IP

I'm working on a websocket extension and would like to grab the host/ip and port of the websocket server when a websocket message is received. Looking at the API it looks like this is not possible, but I'm a newb with Java...

Last updated: May 31, 2023 06:33AM UTC | 1 Agent replies | 1 Community replies | Burp Extensions

HttpRequest.httpRequest() to Proxy?

Newb here. I figured out how to send an HTTP request using montoya but it's not registered by Proxy. Is it possible to send an HTTP request and have it registered by the Proxy tool? Can someone point me in the right...

Last updated: May 26, 2023 03:22PM UTC | 2 Agent replies | 1 Community replies | Burp Extensions

Page 8 of 48

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image