Burp Suite User Forum

Create new post

Filter by highlight color in history tab under proxy

Hello , It would be a useful feature to have a filter based on different colors available for highlighting. One can categorize while testing and then while writing reports , find requests / responses quickly...

Last updated: Jan 16, 2020 09:58PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Meaning of the 'Edited' column in 'Proxy / HTTP history'

Hello, from my experience as a trainer, the meaning of the 'Edited' column in 'Proxy / HTTP history' is quite often misunderstood. In fact, students' expectations are coherent, they just don't match the design choices...

Last updated: Jan 16, 2020 12:09PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

WS-Security (WSS)

Please support OASIS Web Services Security (WSS), or short: WS-Security - https://www.oasis-open.org/committees/tc_home.php?wg_abbrev=wss Soap UI for example already fully supports it:...

Last updated: Jan 13, 2020 02:04PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

XSS into Java Script

Hello, I have a question again. About context into JavaScript, "Terminating the existing script" I understood. The question appears when I go to the lab for practice, >>Reflected XSS into a JavaScript string with single...

Last updated: Jan 13, 2020 08:57AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

XSS contexts / XSS in HTML tag attributes

Hello. I am learning about XSS as you can see, and I can’t understand a little bit about that scriptable context: " autofocus onfocus=alert(document.domain) x=" , I understand what autofocus and onfocus do, but I have no...

Last updated: Jan 07, 2020 10:21AM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Extender callback to add a column to Proxy/Intruder/etc results

Hi, Sometimes it would be useful to have a custom column when displaying history/results - especially for Intruder, but also for Proxy History. This would allow things like Content Length to be shown (vs Length), plus other...

Last updated: Jan 07, 2020 09:27AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Requestin to reset a lab

Hello there i have somehow messed up a lab which is click jacking ui thing. Please do rest the first lab of it.

Last updated: Jan 03, 2020 02:38PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Disable Http Trace Method

Dear Team, Even though i am disabling HTTP Trace method using the Approach mentioned under Issue definition sub tab under Target Tab, but still our burp tool is listing that method as allowable , please suggest any...

Last updated: Jan 02, 2020 10:55AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Multi-Payload encoding rules and Encoding options for Scanner

Hi, It would be nice if you could add support for encoding rules in intruder or scanner. This need comes from many websites where base64 encoded JSONs are used to transfer information between the client and the backend....

Last updated: Dec 30, 2019 10:28PM UTC | 2 Agent replies | 2 Community replies | Feature Requests

Multiply scans at once with Burp Enterprise

I would like to know if there's an option to load multiple/bulk web URLs and schedule scans for multiple/bulk web URLs. If there's an API for this, could you point me to it?

Last updated: Dec 23, 2019 03:51PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Severity / Confidence Labeling - add option of CONFIRMED

When right clicking on an issue, is there any way can you add an additional option of "Confirmed" to the "Set Confidence" menu? (Maybe with a check-mark icon and different colored circle based on severity?) Just as you've...

Last updated: Dec 23, 2019 09:47AM UTC | 2 Agent replies | 3 Community replies | Feature Requests

Allow individual scan audit items to be paused.

I often find myself having to cancel and re-scan an individual audit item when it is slowing down the scan. It would be a great if individual items could be paused and restarted later during the scan.

Last updated: Dec 19, 2019 08:48AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Any access with proxy

Hello, the proxy doesn't work on any computer for me. I have followed the instructions given on your site (burp, browser and certificate configuration). I tried using it on a Mojave Mac OS, Windows 8.1 and Debian 18.04...

Last updated: Dec 09, 2019 09:15AM UTC | 3 Agent replies | 2 Community replies | Feature Requests

Add "Search Bapp Store" Box

The Burp App Store is growing and there are many new additions from last year even. How about a search box that scans the names and description files to filter down the list. So, CSRF will display plug-ins that contain...

Last updated: Dec 03, 2019 09:30PM UTC | 2 Agent replies | 2 Community replies | Feature Requests

Burp Enterprise: Client SSL Certificate Support and Scanner Agent Affinity

Are there plans to implement client certificate authentication (PKCS12 and PKCS11) options/support into Burp Suite Enterprise matching the capabilities of the Pro...

Last updated: Dec 02, 2019 01:01PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Burp XML Parser Functionality in Extender API

Hi, I posted another question in the Customer Portal (found here: https://support.portswigger.net/customer/portal/questions/17672747-xml-tab-reparse-programmatically ) regarding the XML "Reparse" functionality available...

Last updated: Dec 02, 2019 11:21AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

[Burp Enterprise] Configure scan_callback from the web UI

Hi, We would find useful being able to set the scan_callback property allowed by the API when manually configuring scans from the web UI. Is it possible / is it on the roadmap? Thanks, Javi

Last updated: Nov 26, 2019 09:31AM UTC | 3 Agent replies | 3 Community replies | Feature Requests

Match and Replace

Hi, I think that a useful feature in tab Proxy --> Options --> Match and Replace can be the possibility to Duplicate a role. Thanks, Lorenzo

Last updated: Nov 13, 2019 01:11PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Need to extend logging mechanism in burp.

Hello, If someone wants to save logs of all requests for external use the only known for me method is to use Project options -> Misc -> Loggiing. It's because there is no any library (as far as I know) for parsing...

Last updated: Nov 08, 2019 02:21PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Sort Extensions

In the 'Extender' tab, under 'Extensions' it would be useful to be able to sort the extensions by 'Loaded', 'Type', or 'Name'. For example, when clicking the column title.

Last updated: Nov 07, 2019 02:54PM UTC | 2 Agent replies | 2 Community replies | Feature Requests

Page 45 of 66

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image