Extend API Functionality (Stream Proxy + WebSocket)

Hi, I want to write new extensions for BurpSuite, For one of them i need To Set Stream Proxy (PyMultitor), For the other one i need to see WebSocket Raw Sockets To Show And Fuzz Every Parameter.

Sep 26, 2016 | Feature Requests

Custom response grep/extract/post-processing in Burp Intruder?

Burp Intruder supports response grep by regexp, and shows every match in a separate column in result table. It would be helpful to create a custom response processor, written in any language (Python preferred), to...

Sep 22, 2016 | Feature Requests

HTTPS MitM : Export functionality of the per-host generated server certificate / key

Dear In order to be able to decrypt HTTPS traffic in Wireshark[0], one would need the private key linked to the certificate. Would it be possible to include an export functionality of the private key / certificate which...

Sep 19, 2016 | Feature Requests

.NET plugins support

Would be great giving .net support to develop burpsuite plugins

Sep 19, 2016 | Feature Requests

Proxy Intercept window: show proxy listener that received the request

Sometimes I configure Burp with multiple proxy listeners going through the same instance. The Proxy History does a great job at being able to separate the traffic with both a dedicated column for the target port and also a...

Sep 19, 2016 | Feature Requests

Burp Infiltrator destroys Spring Boot application

Hi, when using Burp Infiltrator on a JAR file, which has been created as a Spring Boot application, then the application is not able to start, especially when embedded server is Jetty. Would be great if Burp...

Sep 19, 2016 | Feature Requests

Disable popup window for automatic backups

When automatic backups are enabled, a window pops up and gains operating system focus to display backup process. When Burp is not the active Window, this can interrupt use of other applications. This is common for...

Sep 08, 2016 | Feature Requests

Scanner Check For target="_blank" Vulnerability

Hi Portswigger, I would like to see a check added for links with target="_blank" without the rel="noopener noreferrer" attribute. The author of the below article demonstrates that the site which is linked to is able to...

Sep 07, 2016 | Feature Requests

Add more functionality in "Discover Content"

Hello , you could add more functionality in "Discover Content" like the functionality of a custom list and also an option to stop the specific task(example stop directory brute force in the selected subfolder...)

Sep 06, 2016 | Feature Requests

Make target scope lines clickable

Hi, I'm using Burp Suite Professional v.1.7.05 When visiting Target | Scope, you see a list of targets in scope. Currently only the Enabled column is clickable (it toggles the checkbox). It would be great if you could...

Sep 05, 2016 | Feature Requests

Burp Sequencer feature - Define payload type

Hello, I would like to see a choice for the Sequencer payload type. Meaning if I want to run statistical tests and entropy for 20000 tokens ,I would like to be able to define exactly what type these tokens can be . An...

Sep 03, 2016 | Feature Requests

Requests grab under some actions

Hello. When analyse big targets with many domains, apps, actions, etc, may be very helpfull function of grab group of requests of concrete action. For example, i test big web-app. In some moment, then i have many data in...

Sep 01, 2016 | Feature Requests

Feature request for cookie jar

Hi Just a small request: Would it be possible to add an indication of the cookie flags on cookies stored in cookie jar? That would create an easy overview of the cookies encountered using a test, instead of scrolling...

Aug 25, 2016 | Feature Requests

Numbers Intruder payload: Default the min/max fractional digits fields to 0

Out of all the times I've used the Numbers payload in the span of a year and a half, I think I've only used fractional numbers once or twice. Everyone else in the office here has had a similar experience. Please set...

Aug 17, 2016 | Feature Requests

Confirm closing Intruder/Repeater tabs

Please add a confirmation dialog box when closing these tabs, as they (a) are the easiest to close by mistake, and (b) contain some of the more important information in a session.

Aug 17, 2016 | Feature Requests

Numbers Intruder payload: add support for multiple ranges

Instead of using separate fields for min/max, please change this to a single box that accepts a comma-delimited list of dash-separated inclusive ranges. I.e., 1-50,60-70,80,91-100 (decimal) 0,8-D,20-7E (hex) I think...

Aug 17, 2016 | Feature Requests

Add a processing stack to Grep Extract

Sometimes it's very handy to be able to apply some processing, such as URL or HTML decoding, to extracted values, instead of needing to export to a table (in the case of Intruder results), and then figure out how to apply...

Aug 16, 2016 | Feature Requests

Burp Infiltrator Exclusions

Please add the ability to exclude specific packages or classes from the Burp Infiltrator installer.

Aug 16, 2016 | Feature Requests

Case Modification Intruder payload: add brute force mode

Please add an option that iterates through all the combinations of upper- and lowercase letters for each position. I.e., for an input string "abc", the output should be: abc aBc abC aBC Abc ABc AbC ABC While...

Aug 15, 2016 | Feature Requests

Support CA Certificate Generation for Certs&Keys Greater Than 1024bit

Especially Apple is now enforcing "Best Practices" via App Transport Security. As a workaround I used this guide: https://nabla-c0d3.github.io/blog/2015/12/01/burp-ios9-ats/ Thank you.

Aug 11, 2016 | Feature Requests

