Burp Suite User Forum

Create new post

Grouping Threads for active scan

Hi, would be great if you could allow threads "per group". You dont want to burn one target down, but you might want to test other bits in parallel. An idea would be to allow an identifier set for a group per target...

Last updated: May 08, 2017 10:34AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

NTLM Hash and kerberos ticket support for platform authentication

Currently NTLMv1/v2 platform authentication requires the plaintext password, but often the hash value cannot be cracked easily back into plaintext in an expedient manner. Additionally if the hash is generated based on a 2fa...

Last updated: May 04, 2017 07:41AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Active Scan configuration taken when scan request insered into the queue and not when scan start

Hi everybody, I did some test and seems that currently the active scan configuration is used to generate test cases when the scanner start to execute the tests on a specific request. That mean if you have a long queue and...

Last updated: May 02, 2017 10:51AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Show NTLM auth on requests

Currently NTLM authentication used in burp in not shown in any request and cannot be tracked/checked in anyway. A log should be usefull to check if there is problems. Maurizio

Last updated: Apr 30, 2017 03:49PM UTC | 1 Agent replies | 2 Community replies | Feature Requests

Require Confirmation for Clear History

Please add a confirmation dialog to clear history from the right click menu option. This is far to destructive to the project integrity and irreversible right now.

Last updated: Apr 28, 2017 09:42AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Burp supports Windows 2012 R2

Does Burp supports Windows 2012 R2 ?

Last updated: Apr 26, 2017 08:38AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Server down check

It would be very good to have some sort of keep-alive functionality to ping server whether it is still up, and depending on the pre-set response by user (e.g. custom error message), it would pause Active scanning until the...

Last updated: Apr 25, 2017 10:22AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Burp Infiltrator without DNS lookup

Dear Portswigger Team, Thanks for the brilliant work on Burp Infiltrator. I frequently run Burp Collaborator in internal environments without any outbound Internet connectivity, which means I have to set up Burp...

Last updated: Apr 25, 2017 09:56AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Post-Macro extracting parameter from last response

Hi, I am trying to run a request with a macro and post-macro to do this: Macro1 req1 / resp1 => extract param from rep1 Request get param from from last macro's response req / response (post)Macro2 ...

Last updated: Apr 13, 2017 02:51PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Support for Kerberos Auth.

Any chances this feature will be supported in the near future?

Last updated: Apr 06, 2017 04:46PM UTC | 2 Agent replies | 9 Community replies | Feature Requests

API to modify configuration of scanner via extension

It would be very useful to have API to modify the configuration of the scanner via an extension to run specific active scan with custom configuration (like run scan without cookie etc).

Last updated: Mar 31, 2017 12:43PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

testing

?<iframe src=javascript:alert(419)>

Last updated: Mar 30, 2017 12:30PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

"Resume" for Burp Collaborator Client

Hello, Why can't we restore Burp Colloborator Client? It should be possible for pentesters to also save the results of Burp Collaborator Client and then restore, as with any other Burp tools. Thanks

Last updated: Mar 30, 2017 10:48AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Separated Upstream proxy to Scan

Hi Guys! I have a situation running burp that requires a different upstream proxy for scanning. The idea is, basically allows you to select where the upstream proxy will be applied (Scan, Intruder, Repeater and stuff)....

Last updated: Mar 08, 2017 03:27PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Prevent Burp Proxy from recording some items based on the scope or other filter (e.g. regex)

Hi, I'm looking for a way to prevent Burp from recording some item in the Proxy history. The main reason is that I'm intercepting quite a lot of traffic from the intercepted device, which quickly increases Burp's memory...

Last updated: Mar 08, 2017 03:14PM UTC | 3 Agent replies | 1 Community replies | Feature Requests

improve burp handling of http requests

Hi I will explain the idea by an example, suppose this website " target.com " points to two IPs ( 1.1.1.1 & 2.2.2.2 ) and these IPs has open port " 80 " now we have 4 entry points to test A) when the server...

Last updated: Feb 27, 2017 10:08AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Detect when TRACE response has additional headers we didn't send

I nearly missed it as Burp only showed "HTTP Trace method is enabled" as informational, but actually this was pretty interesting: Request: TRACE / HTTP/1.1 Host: example.com Cookie: 6bwxjeof12 Connection:...

Last updated: Feb 24, 2017 10:25AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Simulate manual testing

So there is this new feature in Burp Pro under Engagement tools named "Simulate manual testing". It is awesome but it would be even better if it could automatically do conf calls with the client and generate the report, Q/A...

Last updated: Feb 09, 2017 09:10AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Post-macros

Hi, Right now macros only can be used as a session handling action to set a parameter or a cookie, but it would be very useful to use them after performing a request to test the contents of another response (for example,...

Last updated: Jan 27, 2017 09:07AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Possibility to sort Name column in the Open existing project panel

It is not possible to sort ASC or DESC by pressing the column name in the Open Existing Project panel. This is very useful to have. Thank you. Keep up the good work.

Last updated: Jan 25, 2017 05:12PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Page 58 of 66

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image