Burp Suite User Forum
Hey ive been trying to find a way to send my profile as a reference for potential work aswell as on social media. Is there any function for that? Seems like a dead end tho. Please introduce this feature (if it doesnt exist...
Could an auto-detect rule be added to detect creds in URI strings? A naive but performant rule could be: \b((?<proto>\w+)://(?<userpass>\w+:\w+)@(?<domainPath>[\w\.:/]+) or...
Would be very nice if it is possible to remove items from the "Queued Tasks" in the content discovery to for example avoid unnecessary discovery tasks. Think this one is easy to implement ;)
Hello, While developing a new Burp extension, I noticed that data related to static analysis is not accessible using the Montoya API. As an example, I have an "Open redirection (DOM-based)" issue in a Burp project with...
Do you give students a discount for burpsuite practitioner exam ?
Hi team, I have been using the montoya APIs for quite sometime now https://portswigger.github.io/burp-extensions-montoya-api/javadoc/burp/api/montoya/proxy/ProxyHttpRequestResponse.html One of the things I'd hoped for...
For the moment only one Platform authentication entry is allowed per destination host. If the user tries to set up a second entry that has the same destination host, Burp will not allow it. However, it is useful during...
In my opinion, the organizer is missing its most important function - organizing. If I want to remember different requests for later in my workflow, I divide them into different categories or put them into groups in the...
I have been bypassing accounts for my work ,but since last week burp suite does not intercept and send the code back to me as a user. Please help me know to bypass a 2 FA account
Within HTTP history, you can currently filter by 2xx, 3xx, 4xx, and 5xx. This feature isn't useful because I typically want to see 200, 301/302, 4xx, and 5xx responses - but I don't want to see 201 No Content, 304 Not...
Add a notification bell so if a user have created a post, and others comment on it. It will be displayed in the notification or Bell Icon. Much like the Youtube Bell Icon
As a learner we have to spend a lot of time spending time reading on Web Security Academy. Therefore, it would be very convenient if we had an option of dark mode too.
when we scan using burp suite and enter a url so does it scan the whole project or that particular URL. Do we need to add all the URL in that project, for...
I'd like to be able to set Burp's default behavior to always show the "Auto-modified" request and response in the HTTP history tab. Thank you.
I'd like to perform in-depth checks on a host-by-host basis. These checks are beyond the current capabilities of BCheck so I can't use the `given host` approach it provides. Montoya can perform checks on a per-request...
I'd like to have a feature where you can search proxy history and export the results to a file. Something along the lines of grep with regex support to save off specific data. I see with Bambdas released, that this might...
Love the new split view on the proxy history with the request/response! The drop down to flip between the original and edited though is a pain. Going back through the proxy history for reporting and flipping between these...
Hello! I just want to start by saying Burp Suite is fantastic, and there is no other tool I would rather use to proxy my Web Application Testing with. I was thinking how it might be nice to have the option to Hide items...
While HTTP and HTTPS servers on the same hostname are sorted together (indicating a degree of custom sorting already), it would really make sense to sort all of the servers in a particular domain together as...
Hi, I have a doubt. Does Burp Suite get better performance to solve Portswigger Academy labs ? I've been taking the Portswigger Academy (using burp suite community license), but some of the labs take too long to...
Page 1 of 62
Your source for help and advice on all things Burp-related.