Burp Suite User Forum
I'm currently working on the web cache poisoning with an unkeyed header lab but whenever I put x=forwarded-host in my header I don't receive a response back. I even tested this by sending the header with just ?cb=1234 and...
Please provide the Burp Suite Features/Data Sheet
Hello, I'd like to to see the progression towards completion under each topic tab in the "learning path" page. Not sure whether it would look cool or not... Maybe make it enable/disable? Thanks for the great resources!
Hi Support, We are in need of testing a web application that relies on google sso pop up, and as you wrote "Burp Scanner is currently unable to replay login sequences that rely on popups or <iframe> elements." there is a...
I'm student. I can't buy PROFESSIONAL License. Can you Please give me a PROFESSIONAL. Can help me with the Pro License. Thank you.
I couldn't find an option or even an extension that takes a list of files and uses the file contents in a POST request. This would be very useful to make file upload function tests more efficient. I imagine a new payload...
Some scan issues contain marker information in the request/response for easier identification of issue, but there is no way to access these markers through the extender API. The IScanIssue.getHttpMessages() function...
Currently facing issues with intercepting the traffic using Burp Suite from a mobile application after whitelisting the public IP address. What is achieved so far: I. Able to intercept the traffic from mobile device’s...
Hello! I think that most business users always use logging. Unfortunately sometimes we forget to turn it on under Project Settings / Misc. Could you put a checkbox in the "New project on disk" section of the opening screen...
Can you reset all my labs expect sql injection and path traversal.
Hi, Recently we are seeing nessus vulnerability issue regarding the oracle java version as below: Plugins: 166316 Oracle Java SE Multiple Vulnerabilities (October 2022 CPU). "<plugin_output> Path :...
Hi, Team: We can upload more than two configuration files for a site in Burp Suite Enterprise (Settings > Configuration). but how does Burp Suite Enterprise choose when two configuration files conflict? The A...
Hi, I raised this issue a year or two back (don't recall the outcome, but it is not yet a feature)and wanted to raise it and one other again. The Content Discovery feature produces too much noise in its default...
A user by selecting multiple plugins from the list can be enabled using a single click without each extension opening a separate widow. Include a separate tab to show which extensions did not load and their respective...
When selecting text on repeater, on inspector it shows the number of bytes. It would be helpfull to see the number of bytes also in Dec but also in Hex. In particular when performing http smuggling attacks (transfer...
Dreamtime / blue sky request :-D Sometimes I'm in a situation where burp is installed on a machine that's not internet connected, but I'd still like to use the collaborator. It would be awesome if there could be a mobile...
Hello, I have reached my license limit. I have activated the license in several VMs on my personal computer. If possible I'd require an additional activation.
Can anyone tell me how to bypass mega account recovery key it is important to me it has 10 bitcoin in it whoever securely bypass it I give 2 bitcoin to it.
hi, Does Burp Suite Enterprise Edition support the use of a private Burp Collaborator? and how could it be used? thanks!
Is it possible to provide UDP source ports of DNS queries via the IBurpCollaboratorInteraction interface? This would allow to easily analyze the randomness of used source ports, which makes it possible to find...
Page 4 of 56
Your source for help and advice on all things Burp-related.