Burp Suite User Forum
Hello. When analyse big targets with many domains, apps, actions, etc, may be very helpfull function of grab group of requests of concrete action. For example, i test big web-app. In some moment, then i have many data in...
Hi Just a small request: Would it be possible to add an indication of the cookie flags on cookies stored in cookie jar? That would create an easy overview of the cookies encountered using a test, instead of scrolling...
Out of all the times I've used the Numbers payload in the span of a year and a half, I think I've only used fractional numbers once or twice. Everyone else in the office here has had a similar experience. Please set...
Please add a confirmation dialog box when closing these tabs, as they (a) are the easiest to close by mistake, and (b) contain some of the more important information in a session.
Instead of using separate fields for min/max, please change this to a single box that accepts a comma-delimited list of dash-separated inclusive ranges. I.e., 1-50,60-70,80,91-100 (decimal) 0,8-D,20-7E (hex) I think...
Sometimes it's very handy to be able to apply some processing, such as URL or HTML decoding, to extracted values, instead of needing to export to a table (in the case of Intruder results), and then figure out how to apply...
Please add the ability to exclude specific packages or classes from the Burp Infiltrator installer.
Please add an option that iterates through all the combinations of upper- and lowercase letters for each position. I.e., for an input string "abc", the output should be: abc aBc abC aBC Abc ABc AbC ABC While...
Especially Apple is now enforcing "Best Practices" via App Transport Security. As a workaround I used this guide: https://nabla-c0d3.github.io/blog/2015/12/01/burp-ios9-ats/ Thank you.
Hi ! I have scanned a target address and found "External service interaction (DNS)" vulnerability. Is this related to DNS Zone Transfer? and How do i rate this vulnerability according to 1 to 10? please help me ASAP...
There have been times that I've opened a project file, or returned to a project and forgot Live Active Scanning is enabled. Since almost every action in burp is very explicit, requiring user interaction. When live active...
It is a common use case to want repeater to use the current cookie from the cookie jar. However sometime you want to make sure session authentication is working properly, so you intentionally want to use an old...
Hi, I don't have a convenient way to view responses with bodies that are XML encoded in utf-16. I think handling this would involve a coding change, but if there's a configuration I've overlooked, please let me...
An option to disable update checks on startup would be great. This setting should also disable update checks when upstream proxy server settings are changed. This would be especially useful for Burp users that test in...
When testing session tokens, usually the same request is sent over and over again to the server. Often this causes a considerable amount of load (as tests are usually made on test/quality/integration systems with lower...
Hi all, I am a visually impaired Burp user who unfortunately, cannot use Burp itself due to the native UI being completely unusable with screen readers. Therefore, I only have one remaining usability option; interact with...
When there are hundreds or even thousands of pages to scan it it isn't always the best use of time to attempt to weed out and try to select which items to scan or determine which ones are nearly identical except a...
I'm part of an iterative security testing effort where I provide engineers with an issue report, they make fixes, repeat. We are trying to measure how successful each iteration is, meaning did security flaws from report 1...
Hi team: Logging options are able to select the tool that you want log and select request or response, but I think that is necessary add a field where you can define a regular expression to log only the request and/or...
It would be great to have multiple cookie jars to operate with. Macros/Rules could specify which cookie jar they want to use and also a global option could specify the default cookie jar to maintain the current behaviour....
Page 56 of 62
Your source for help and advice on all things Burp-related.