Burp Suite User Forum

Login to post

Link your profile for social media etc

Hey ive been trying to find a way to send my profile as a reference for potential work aswell as on social media. Is there any function for that? Seems like a dead end tho. Please introduce this feature (if it doesnt exist...

Last updated: Dec 11, 2023 11:28AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Issue Discovery - URIs with creds

Could an auto-detect rule be added to detect creds in URI strings? A naive but performant rule could be: \b((?<proto>\w+)://(?<userpass>\w+:\w+)@(?<domainPath>[\w\.:/]+) or...

Last updated: Dec 11, 2023 09:45AM UTC | 2 Agent replies | 2 Community replies | Feature Requests

Content Discovery remove items from Queued Tasks

Would be very nice if it is possible to remove items from the "Queued Tasks" in the content discovery to for example avoid unnecessary discovery tasks. Think this one is easy to implement ;)

Last updated: Dec 07, 2023 12:25PM UTC | 6 Agent replies | 6 Community replies | Feature Requests

Static analysis data exposed through Montoya API

Hello, While developing a new Burp extension, I noticed that data related to static analysis is not accessible using the Montoya API. As an example, I have an "Open redirection (DOM-based)" issue in a Burp project with...

Last updated: Dec 04, 2023 11:54AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Exam

Do you give students a discount for burpsuite practitioner exam ?

Last updated: Dec 04, 2023 10:00AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

HTTP Proxy Mutating Methods

Hi team, I have been using the montoya APIs for quite sometime now https://portswigger.github.io/burp-extensions-montoya-api/javadoc/burp/api/montoya/proxy/ProxyHttpRequestResponse.html One of the things I'd hoped for...

Last updated: Dec 01, 2023 02:09PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Platform Authentication settings: allow multiple entries with same host

For the moment only one Platform authentication entry is allowed per destination host. If the user tries to set up a second entry that has the same destination host, Burp will not allow it. However, it is useful during...

Last updated: Nov 29, 2023 11:33AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Organizer

In my opinion, the organizer is missing its most important function - organizing. If I want to remember different requests for later in my workflow, I divide them into different categories or put them into groups in the...

Last updated: Nov 29, 2023 11:22AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Bypassing an account

I have been bypassing accounts for my work ,but since last week burp suite does not intercept and send the code back to me as a user. Please help me know to bypass a 2 FA account

Last updated: Nov 28, 2023 04:32PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

More Granularity For "Filter by status code" Setting

Within HTTP history, you can currently filter by 2xx, 3xx, 4xx, and 5xx. This feature isn't useful because I typically want to see 200, 301/302, 4xx, and 5xx responses - but I don't want to see 201 No Content, 304 Not...

Last updated: Nov 28, 2023 03:56PM UTC | 2 Agent replies | 3 Community replies | Feature Requests

Notification Bell on The Website

Add a notification bell so if a user have created a post, and others comment on it. It will be displayed in the notification or Bell Icon. Much like the Youtube Bell Icon

Last updated: Nov 28, 2023 09:10AM UTC | 3 Agent replies | 1 Community replies | Feature Requests

Dark Mode for Web Security Academy

As a learner we have to spend a lot of time spending time reading on Web Security Academy. Therefore, it would be very convenient if we had an option of dark mode too.

Last updated: Nov 27, 2023 10:58AM UTC | 14 Agent replies | 22 Community replies | Feature Requests

when we scan using burp suite and enter a url so does it scan the whole project or that particular URL

when we scan using burp suite and enter a url so does it scan the whole project or that particular URL. Do we need to add all the URL in that project, for...

Last updated: Nov 22, 2023 10:42AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Option to make "Auto-modified request" the default view option in HTTP history

I'd like to be able to set Burp's default behavior to always show the "Auto-modified" request and response in the HTTP history tab. Thank you.

Last updated: Nov 21, 2023 03:33PM UTC | 3 Agent replies | 2 Community replies | Feature Requests

Montoya equivalent of BCheck 'given host'

I'd like to perform in-depth checks on a host-by-host basis. These checks are beyond the current capabilities of BCheck so I can't use the `given host` approach it provides. Montoya can perform checks on a per-request...

Last updated: Nov 17, 2023 01:08PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Export searched data from proxy history

I'd like to have a feature where you can search proxy history and export the results to a file. Something along the lines of grep with regex support to save off specific data. I see with Bambdas released, that this might...

Last updated: Nov 15, 2023 04:32PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Proxy Original Request Vs Edited Request

Love the new split view on the proxy history with the request/response! The drop down to flip between the original and edited though is a pain. Going back through the proxy history for reporting and flipping between these...

Last updated: Nov 15, 2023 01:30PM UTC | 7 Agent replies | 7 Community replies | Feature Requests

Filter - Hide Items Excluded from Scope

Hello! I just want to start by saying Burp Suite is fantastic, and there is no other tool I would rather use to proxy my Web Application Testing with. I was thinking how it might be nice to have the option to Hide items...

Last updated: Nov 13, 2023 02:36PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Sort entries in the site map by domain components before hostname

While HTTP and HTTPS servers on the same hostname are sorted together (indicating a degree of custom sorting already), it would really make sense to sort all of the servers in a particular domain together as...

Last updated: Nov 10, 2023 02:47PM UTC | 3 Agent replies | 3 Community replies | Feature Requests

Do I need Burp Professional license to take Portswigger Academy course?

Hi, I have a doubt. Does Burp Suite get better performance to solve Portswigger Academy labs ? I've been taking the Portswigger Academy (using burp suite community license), but some of the labs take too long to...

Last updated: Nov 09, 2023 01:04PM UTC | 3 Agent replies | 3 Community replies | Feature Requests

Page 1 of 62

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image