Burp Suite User Forum

Login to post

API to update Requests as presented in UI in Proxy, Repeater, etc.

Hi, I have written some custom extensions using both the java API and jython. Typically, it is for things like setting custom headers. While they work (they do send the custom headers) it's hard to see exactly what was...

Last updated: Apr 22, 2015 08:29AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

XML formatting

Would it be possible for Burp Suite to properly format XML requests in the 'Params' tab? Cheers.

Last updated: Apr 20, 2015 08:47AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

In scanner, Setting a configration of redirection

I would like to set up redirection in scanner in the same way as intruder/repeater. Scanner can only set up valid/invalid. (It is the check box "Follow redirections where necessary")

Last updated: Apr 07, 2015 08:39AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

In intruder, setting up payload with "Grep - Match"

When I use intruder, I have to set up payload and "Grep - Match" each time. So I would like to set up them same time.

Last updated: Apr 07, 2015 08:37AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Load Macro Parameter from File

When configuring a macro item, each parameter's value has the option of "Use preset value" or "Derive from prior response". I'd like the capability to load a parameter's value from a file at runtime by specifying a...

Last updated: Apr 03, 2015 06:07PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Decoder enhancements - user interface

Two items to request (both mentioned in former user forum): 1. Multiple decoder tabs (self-explanatory) 2. Clipboard context menu within the input field. This seems simple enough, but essentially this will give users...

Last updated: Apr 02, 2015 10:52AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Decoder enhancements - algorithms

To minimize switching between Burp and other tools for crypto-analysis, add more options to Burp's Decoder. Here are a few suggestions: - keyed algorithms (DES, 3DES, AES, XOR, ROTn, etc) - Anything OpenSSL enc/dec...

Last updated: Apr 02, 2015 10:50AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Showing Current Request with the Last Response from the Macro

When using Intruder/Repeater with "Post Request Macro" and setting "Pass back to the invoking tool:" = "The final response from the macro", Intruder/Repeater only show the pair of "the final request sent by Post Request...

Last updated: Apr 02, 2015 09:06AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Feature Request - intruder/scanner

Hi Team, I am Takeshi Sato from Japan. I am always using burp on my work so I have some feature requests. First request is regarding intruder. When I am using intruder, I often change the payload and I have to change...

Last updated: Apr 01, 2015 10:21PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Auto start certain Engagement tools

Target > Site map > right click on target URL > Engagement tools: Find comments - should auto start Find scripts - should auto start Find references already does this.

Last updated: Mar 12, 2015 03:52PM UTC | 2 Agent replies | 0 Community replies | Feature Requests

Add tests for SQL injection with Tabs rather than Spaces?

I was working through the Pentester Lab: Web For Pentester (https://www.vulnhub.com/entry/pentester-lab-web-for-pentester,71/) SQL injections, and the Example 2 injection rejects all inputs with spaces in them. Using TAB...

Last updated: Mar 09, 2015 04:15PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Out-of-Scope Requests

The following section: Options > Connections > Out-of-Scope Requests should be moved to Target Scope.

Last updated: Mar 05, 2015 01:58PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Every time the Burp is started, the previous Target - Scope and the Target Filter are reset.

Every time the Burp is started, the previous Target - Scope and the Target Filter are reset.

Last updated: Feb 25, 2015 03:07PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

save state wizard. (Exclude static content, Exclude by file extension)

Hi, result: huge state file. why? huge static web application with few dynamic pages New feature on the save state wizard: Exclude static content / export dynamic content only Exclude by file extension Thanks in...

Last updated: Feb 24, 2015 02:42PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Ability to Add to Scope from Proxy Intercept Tab

I do not believe this is possible today but I would like if there was an option "Add to scope" as one of the options under "Action" when intercepting packets. Thanks!

Last updated: Feb 13, 2015 09:51AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

State Management - Display the current State

During an engagement I will work with and save multiple states. Once I load or save a state I would like Burp to display the current state loaded. I tt would make it easier to manage all the various files. It would also...

Last updated: Feb 13, 2015 09:26AM UTC | 3 Agent replies | 2 Community replies | Feature Requests

PHP extract() vulnerabilities

Please see this post about the risks of using PHP function extract() improperly: http://davidnoren.com/2013/07/03/php-extract-vulnerability/ At the end of the post are a few ideas on how to test for it. Unsure if those...

Last updated: Feb 10, 2015 11:58AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Remove duplicates

Scanner > Scan queue > sort by URL. Need a way to right-click and say "Remove Duplicates".

Last updated: Feb 02, 2015 10:39AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Automatically add repeater results to the site map

Hello, It would be nice if an option could be added to automatically add the repeater results to the site map. I work quite a lot with the repeater and it could be nice to have a direct access to search and other...

Last updated: Jan 29, 2015 01:51PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Ability to edit several rows on parameters viewing tab during editing of intercepted message

Ability to edit several rows (i.e. values/names of several POST parameters) on parameters viewing tab during editing of intercepted message (Proxy module) would helped a lot.

Last updated: Jan 26, 2015 10:04AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Page 33 of 34

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image