Burp Suite User Forum

Create new post

"Resume" for Burp Collaborator Client

Hello, Why can't we restore Burp Colloborator Client? It should be possible for pentesters to also save the results of Burp Collaborator Client and then restore, as with any other Burp tools. Thanks

Last updated: Mar 30, 2017 10:48AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Separated Upstream proxy to Scan

Hi Guys! I have a situation running burp that requires a different upstream proxy for scanning. The idea is, basically allows you to select where the upstream proxy will be applied (Scan, Intruder, Repeater and stuff)....

Last updated: Mar 08, 2017 03:27PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Prevent Burp Proxy from recording some items based on the scope or other filter (e.g. regex)

Hi, I'm looking for a way to prevent Burp from recording some item in the Proxy history. The main reason is that I'm intercepting quite a lot of traffic from the intercepted device, which quickly increases Burp's memory...

Last updated: Mar 08, 2017 03:14PM UTC | 3 Agent replies | 1 Community replies | Feature Requests

improve burp handling of http requests

Hi I will explain the idea by an example, suppose this website " target.com " points to two IPs ( 1.1.1.1 & 2.2.2.2 ) and these IPs has open port " 80 " now we have 4 entry points to test A) when the server...

Last updated: Feb 27, 2017 10:08AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Detect when TRACE response has additional headers we didn't send

I nearly missed it as Burp only showed "HTTP Trace method is enabled" as informational, but actually this was pretty interesting: Request: TRACE / HTTP/1.1 Host: example.com Cookie: 6bwxjeof12 Connection:...

Last updated: Feb 24, 2017 10:25AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Simulate manual testing

So there is this new feature in Burp Pro under Engagement tools named "Simulate manual testing". It is awesome but it would be even better if it could automatically do conf calls with the client and generate the report, Q/A...

Last updated: Feb 09, 2017 09:10AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Post-macros

Hi, Right now macros only can be used as a session handling action to set a parameter or a cookie, but it would be very useful to use them after performing a request to test the contents of another response (for example,...

Last updated: Jan 27, 2017 09:07AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Possibility to sort Name column in the Open existing project panel

It is not possible to sort ASC or DESC by pressing the column name in the Open Existing Project panel. This is very useful to have. Thank you. Keep up the good work.

Last updated: Jan 25, 2017 05:12PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Requesting a feature that allows us to automatically intercept all responses

As far as I know, to intercept a response, I must manually intercept the response for that request using the Action button. A feature that would allow me to intercept all responses without having to go through the action...

Last updated: Jan 25, 2017 03:23PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Global Regex Rules

Hello all, I would like to see a feature similar to "Proxy->Options>Match and Replace" that would affect not only the requests proxied by Burp but all the request within Burp. I explain, sometime, I would spider and...

Last updated: Jan 17, 2017 11:55AM UTC | 0 Agent replies | 1 Community replies | Feature Requests

Spider and Scanner History

We were performing an application penetration test on an internal production application with the Spider on.Now, blame it on whoever , our pentesters forgot to turn off the Form submitting feature of Spider and it went ahead...

Last updated: Jan 13, 2017 09:38AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Mark targets as preferred - Site Map

Hi Team, While we perform an assessment for any webpage it shows all the sites under Site Map, but we have only limited sites under assessment scope on which we want to focus. A tag to mark some site as preferred (moving...

Last updated: Jan 04, 2017 12:00PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Burp 2FA integration - Disable human intervention during 2FA process

Hi, In today's best practice, medium risk and above applications implement some form of 2FA solution with sensitive functionality like authentication , forgot password, enabling transaction, account activation...

Last updated: Jan 03, 2017 10:21AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Programming interface

That would be great if Burpsuite has a programming interface like fiddlerscript in fiddler. That will allow tester to explore more potential of burpsuite and the requests made.

Last updated: Dec 23, 2016 09:13AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Allow Repeater to execute a request several times

The Intruder option does not work for multipart/form-data requests with binary data. The Intruder tries to interpret the § symbols within the binary data and thinks these are payload locations. The Repeater should have a...

Last updated: Dec 22, 2016 09:19AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Target organization

When following a manual testing workflow, I prefer to reference the site hierarchy under the Target tab, but there is no way to track progress or my remarks internally. If paths could be color-coded and allow comments or...

Last updated: Dec 19, 2016 04:58PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Options to match & replace from existing message (like regex backreferences)

Hi, I'd like to request a feature in Proxy's Options- Match & Replaces where I can find a match, and replace it with existing messages. For clarity, suppose I want to append Origin header in each requests, but I want...

Last updated: Dec 16, 2016 10:42AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

"Parameter values extractor"

Basically this is an advanced search feature which gives a list of all values assigned to a parameter. The parameter can appear either in GET, POST, etc. requests or responses, or JSON, XML, etc. messages. The...

Last updated: Dec 14, 2016 06:06PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Session Handling Rule - On Failure - Switch Proxy

I sometimes find in performing test that there are devices in place that lock out web activities for 5-10 mins if too many perceived attacks are seen. I think it would be great to have a session handling rule that would...

Last updated: Dec 01, 2016 09:25AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

partial JSON config files

Currently when starting a new burp project and loading it with a config file, you have to have every option filled in the JSON, otherwise it'll leave that field as blank in the new project. I'd really like it if you could...

Last updated: Nov 29, 2016 04:50PM UTC | 2 Agent replies | 0 Community replies | Feature Requests

Page 56 of 64

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image