Burp Suite User Forum

Create new post

disable Payload encoding and auto load payloads through API

It would be nice if the payloads get automatically loaded from custom file when invoking sendToIntruder method and API method to disable URL encode these characters through API. Thereby launching the attack through API

Last updated: Apr 25, 2016 03:05AM UTC | 2 Agent replies | 3 Community replies | Feature Requests

Proxy: Warn when leaving the project scope

It would be a nice little feature for manual testing if burp would show a warning in the browser, when leaving the configured scope while browsing a site. The warning should only be displayed in the browser and give a...

Last updated: Apr 20, 2016 07:56AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Workbench for items that one wants to take a closer look on later

It'd be a neat feature if burp would have some sort of "Workbench", where one could send requests to that one wants to inspect later. I often find myself in a situation where I'm quickly checking autoscan results and...

Last updated: Apr 18, 2016 10:41AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Restore scan queue issues column

I have been using Burp for many years and appreciate all the updates and features. One feature/bug that have been bugging (pardon the pun) me is when one restores a previous Burp state, the Issues column in the scan queue...

Last updated: Apr 13, 2016 08:21AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Pass back in "Run post-request macro"

Currently, a session handling rule running a post-request macro can pass back to the invoking tool either: - the response from the current request - the final response from the macro In multi-step work-flows, it is...

Last updated: Apr 11, 2016 09:08PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Not only log time but also log date

L.S. I use Burp Suite to log browser activity for a long period. Within the log on disk and on the HTTP history only the time of a request/response, not the date, is logged. Could you please also log the date in a...

Last updated: Apr 10, 2016 08:59AM UTC | 1 Agent replies | 0 Community replies | Feature Requests


Does Burpsuite or any of its add ons support checks for NoSQL databases?

Last updated: Apr 06, 2016 07:24PM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Audible Alerts

Would like to add this feature - where is a error - say network issue that has made the scan to stop - in that case, we would like to have a audible alert. This would help the user to focus his attention on other tasks...

Last updated: Apr 04, 2016 07:34PM UTC | 0 Agent replies | 1 Community replies | Feature Requests

Filter Bypass Scanner Options

Filter bypass options for the scanner would be useful. Just from a SQLi perspective, it would be great if I could have radio buttons that could enable SQLmap tamper script style payload modification options such as...

Last updated: Mar 14, 2016 09:28AM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Add a parameter to the scanner exclude list via right-click context menu on the Param tab

I hope it doesn't take much work to add this feature to the current version. It would really be helpful if you can just right click on any parameter and add them to the exclude list of scanner rather than doing a copy and...

Last updated: Mar 07, 2016 02:28PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Log Files

I would like to ask for a feature that would allow me to choose a maximum file size for each log type(much like what i do with tshark for packet capturing). This would force burp to create a new log file everytime the file...

Last updated: Mar 06, 2016 08:18PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Burp Extender - Support for more details from IScanQueueItem

Hi Burp Team, Good day! We have been using active scanner in our CI builds on a regular basis. However, sometime active scan queue items get stuck/slow/become stale and they appear to make little to no progress for a...

Last updated: Mar 04, 2016 07:23AM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Proxy Intercept modify + encode

Hi, It would be nice to add to the "Match and Replace" feature of the Proxy Options the possibility to not only add and replace but to encode, or even do the same as with the intruder payload processing (adding rules in a...

Last updated: Mar 02, 2016 04:18PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Page Deduplication

Some applications offer a large set of sites that only present different data but are based on the same template. This can result in thousands of pages in the scope that are basically irrelevant. There should be some way...

Last updated: Feb 26, 2016 01:35PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

In intruder, putting add positions properly to JSON type request

When I assess the JSON type request, intruder put the add position like below: testparameter=${"user":"admin","password": "password00"}$ I would like to put the target position like...

Last updated: Feb 18, 2016 05:24PM UTC | 2 Agent replies | 0 Community replies | Feature Requests

Show base request variable in intruder

When running an attack with intruder, particularly a Sniper attack with number payload, it would be good if in the Payload field, the base request (request ID 0) displayed what the contents were between the $$ symbols. At...

Last updated: Feb 17, 2016 11:41AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Keyboard shortcut - Clear history and ALT-TAB

Can you add the ability to: a) Do things without confirmation if I so want? Clear History for example, close Burp for another. And generally do think of other common tasks and add the ability to do things with keyboard...

Last updated: Feb 11, 2016 08:23PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Display file name in Burp's caption bar

Perhaps this was already requested. If so, please ignore this request. I routinely save multiple proxy logs for the same application, depending on the type of test I'm conducting. At times I use several instances of Burp...

Last updated: Feb 11, 2016 05:26PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Differential Automatic Backup Functionality

Automatic Backup is fantastic, it saved our work quite some time, when the Java environment decided to give up and crash. But, storing every time 700 megs, for example, in a state file, will fill up any hard drive over a...

Last updated: Feb 01, 2016 08:48AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Automatic backup prefix

Hi, it would nice to have an option to set prefix for automatic backup file name. When I am working on project1, I would like easy to set up prefix 'project1'. Then I can switch i.e. to project2...

Last updated: Jan 31, 2016 09:15AM UTC | 2 Agent replies | 1 Community replies | Feature Requests

Page 62 of 66

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image