Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
Hi, can you please reset all my learning paths and completed labs? Thanks.
Hi Team, Could you please reset all my labs
Unable to intercept Https traffic in firefox and pre configured browser , not able to open any websites like google ,fb etc. I've installed the certificate on firefox, still facing same issue.
Hi Team, We'd like to propose a feature which will add up to the usability of Burp Enterprise in Enterprise environments - Tagging. Currently we can group our sites\targets in folders and subfolders, which allows us to...
After completing 100 Mystic Labs at PortSwigger, I noticed that some labs appear very frequently, while others hardly appear at all. This repetition can limit the variety of challenges and affect the learning experience....
First of all, thank you for your fantastic Tool burp suite. I would like to ask for improved functionality to hide uninteresting headers. Could you add in the options or where you think is best a list where you indicate...
Hi! Currently, displaying a request+response pair side-by-side is only possible in Repeater ("Repeater -> View -> Left/right split" from the menu bar) or via extensions like Flow or Logger++. I use this layout a lot and...
Hi, Creating PoC pictures from Burp properly takes some effort to minimize requests (I know, there is extension for it). Also, on smaller screens (e.g. laptop), one sees the same headers over and over again, which for all...
In "Discover content," under what circumstances do you consider content to have been discovered? My guess is that it's when a status code other than 404 is returned. Is there any other logic behind this? Also, I don't...
We are currently building a tool for extracting pre-master secret (PMS) values from memory of mobile devices. It would be great if Burp supported the decryption of TLS traffic with a list of PMS values just like Wireshark...
Hi, I want to reset both my lab progress and my learning path progress. Thanks
i want to rest all my progress and labs
Hi, in an assessment I had to pentest an application which uses websockets. After a bit of fuzzing I found out, that a invalid payload caused the application to close the websocket-connection with an...
When doing an Active Scan, you can enter a username/password combination or record requests that will authenticate. MFA disrupts this workflow. I suggest adding an option to add a header (eg. authorization) or authentication...
I noticed the withTransformationApplied method and would like to suggest adding a potential HttpTransformation.HTTP_VERSION to the backlog. This could facilitate switching HTTP versions more seamlessly. For example, you...
i Solve this Lab by just submiting this code since it Redirect us automaticly to social-login page and complete oauth flow when trying to change the email: <html> <body> <form...
Hi, I feel I may have asked about this before but mainly just want to see if its something on the radar. We have a few company-wide Bambdas, and would like to have these imported by default to each consultant. I can't see...
... X-Forwarded-For: 1.1.1.1 X-Forwarded-For: ... In this form, i need to add two identical headers, but the session processing rules will only apply to one put the same header. I've looked for extensions, but...
Would be great to have a log side tab for each repeater tab (e.g. next to the Inspector and notes side tabs). I know you can kind of navigate through previous requests with the arrows/dropdowns next to the Send and Cancel...
Hello! I was wondering if it would be feasible to add the ability to alter requests in paused scans. The main use case I've run into where this would be helpful is scanning requests in apps with short session times where...
Page 3 of 68
Your source for help and advice on all things Burp-related.