Burp Suite User Forum
Hey, I often want to bruteforce IDs, specifically integers. I use the `Numbers` payload in Intruder. But it requires the following configuration: - Min/max integer digits - Min/max fraction digits This means every...
Please create a two-way integration for ServiceNow. You can see an ideal integration here, https://www.netsparker.com/support/integrating-netsparker-enterprise-servicenow/ Notice the availability for the SN ticket to...
Hi everyone, I've seen that "OAuth" is not on your "prior list" and i don't understand why. Everything is an API at the moment, it should be on your prior list to add this feature. Actually i need to test 2 privates...
It would be very handy in my opinion to have the proxy history splitted sometimes, to compare login request flows.
Hi, We are attempting to use Enterprise's REST API Scanning feature. We understand the published limitations, which do not allow for Authorization or Additional headers to be specified in the OpenAPI Specification....
I'd like to be able to add a comment for why an issue has been marked as a false positive. I'd like those comments to be available to be included in scan reports as well.
OWASP ZAP shows the RTT in the request history which makes it very easy to manually test and spot potential timing based attacks. I know these timings can been tested / seen in the repeater and intruder... but knowing which...
It's really useful to save some intruder attacks to the project file. However, without a way to name them on the dashboard, it can be hard to find the correct one. I know you can name intruder tabs, but this name doesnt seem...
hello best app ever is there anyway to auto replace websocket request messages ? or if there are any extension do that can someone show us how :D
Please delete my account
Can you please add the ability to Decoder to encode the special URL and HTML characters only? The need to do this comes up quite often during application testing. For example, when looking at the first lab of the burp...
Hello Team, This is Himanshu. I have purchased a burp suite certified practitioner exam on 5th oct 2021. Can i give the exam tomorrow i.e; on 5th oct 2022 or 4th oct 2022 is the last day to give exam.? Thank...
Hi I would like to suggest inclusion of a new function: the possibility of excluding some HTTP-status codes in the responses in the "Content discovery" tool. I see that some sites like to "bounce you back" with 301s. You...
The "Delete item(s)" item submenu feature in Intruder is missing for a lot of time now. E.g., version 2020.6 still has it, but from that version to today somewhere in the middle it was removed. Newer version cannot delete...
Hey all, so when testing websites which are big and interconnected, lots of different API endpoints, sometimes even x-site - one (at least I) do not want to use the Scope Feature. (Sidenote: I very rarely use the scope...
I want to find out whether a user uses light mode or dark mode using the Extender API, so that I can pick an appropriate font color in my extension. The new Montoya API has a Theme enum, but there doesn't seem to be any...
Consider the following scenario: For logging in, you need to have a valid CSRF token. The standard way to solve that in Burp is to use a macro that fetches the token. But in this web app, the token is unique for every...
I would like to be able to use the keyboard arrow keys to navigate up and down on the Dashboard > Issue activity panel when it has focus. I would like it to work exactly the same way as using the arrows keys to navigate...
I just migrated from windows laptop to another laptop, I activated license twice in windows and vm on the host. When I tried to activate burp pro in arch, it showed the issue 'No more activations allowed for this license'. I...
like the follow redirect button, it would be nice to have a button to set all cookies
Page 5 of 56
Your source for help and advice on all things Burp-related.