Burp Suite User Forum

Create new post

Collaborator Server Version

Hi, While doing a Health Check on the Collaborator Server it would help if it returned the Version #. Especially for making sure a Private Server is up to date. Thanks

Last updated: Sep 22, 2015 07:48AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Duplicate entries in scan queue

Why does Burp make duplicate entries with a status of "waiting" in the scan queue. It seems trivial to scan the list in code prior to the addition of a new URL and to not add it if there is already one there. I am requesting...

Last updated: Sep 18, 2015 08:03AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Use Other Burp Instance on Different Port as an Upstream Proxy to see Scanner requests

If I want to see what requests are being sent by scanner, I usually run another Burp proxy instance and set my Upstream proxy to it. In that way when I look at the proxy history tab of that other burp proxy instance, I'd be...

Last updated: Sep 15, 2015 10:52AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Burp Testing Methodologies

Findings should include links to relavent Burp Testing Methodologies: https://support.portswigger.net/customer/portal/topics/792273-burp-testing-methodologies/articles?page=1

Last updated: Sep 14, 2015 03:42PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Session handling rule action - replace part of request

Hi, I'd like to propose a new session handling rule action that would basically replace any part of a request with a predefined constant. Just like s/const1/const2/g in vi would do. Thanks, PSi

Last updated: Sep 14, 2015 12:28PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Additional step for scanner options when launching active scanner.

It would be awesome to have an additional step when launching an active scan, for configuring what are the parameters that we want to scan without have to mess with the general config. For example: Lets say that for this...

Last updated: Sep 14, 2015 11:48AM UTC | 2 Agent replies | 4 Community replies | Feature Requests

"onmouseover="prompt(1);"

"'><li onmousover=alert(1)>xxx</li>

Last updated: Aug 28, 2015 01:06PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

IS there any new vulnerability introduced??

IS there any new vulnerability introduced apart from OWASP top ten.

Last updated: Aug 10, 2015 08:02AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

setting case sensitivity option

When I'm sure I'm testing Windows environment and it doesn't matter on sensitivity, would it be possible to introduce an option where this could be turned on? I noticed that e.g. in Target Analyzer -> Parameters you are...

Last updated: Jul 31, 2015 01:17PM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Save All Repeater Tabs in State File

See bug report here for context: https://support.portswigger.net/customer/portal/questions/11548096-not-all-repeater-tabs-saved-restored-via-state-file I send requests to Repeater as I explore an application, and go back...

Last updated: Jul 22, 2015 07:13PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Feature request (other ssl/tls protocol support)

What would compliment this great tool is the ability to support other protocols that run on SSL/TLS like SMTP secure and IMAP secure. There are other proxy like tools out there for these protocol yet none of them provide...

Last updated: Jul 21, 2015 07:48PM UTC | 1 Agent replies | 1 Community replies | Feature Requests

Intercept Queue

Would it be possible to add a "Queue" to the Intercept tab. This would show the requests/responses queued to be intercepted and they would be removed from the queue after they are intercepted. On occasions where there are...

Last updated: Jul 19, 2015 01:46PM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Add "Close All Tabs" button to the Repeaster

In the repeater tab, I would like a “close all tabs” button. In the Mac-look-and-feel-GUI; if you click the X, the tabs auto-adjust slightly to re-center. Thus, you click X and move the mouse. Repeat 52 times (yes, I had...

Last updated: Jul 08, 2015 10:43AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

ASP.NET ValidateRequest bypass + tuning

According to my experience Burp Suite doesn't check for this type of ValidateRequest filter bypass: http://www.jardinesoftware.net/2011/07/17/bypassing-validaterequest/ Would it be possible to add this to the...

Last updated: Jul 08, 2015 08:02AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Hide from view based on MIME type

Hi, recently I came across a web server where certain categories of files (images, css) were having a filename of the format "_x-y" with no extension, where x and y is a alphanumeric value of a varying length of characters,...

Last updated: Jul 06, 2015 12:29PM UTC | 0 Agent replies | 1 Community replies | Feature Requests

Match -> Match/Replace.

I would like to beg this request again, as there is a need for feature. Here the use case. I would like to be able to Match/Replace based on Matching a different value. I have been told to write it myself, but that...

Last updated: Jul 03, 2015 07:06PM UTC | 1 Agent replies | 2 Community replies | Feature Requests

Provide option to pass unaltered response back to client

Recently we conducted an application assessment for an android application. The application communicated using gzip / deflate content encoding. Burp Suite was initially configured to unpack gzip/deflate encoded traffic via...

Last updated: Jun 29, 2015 10:11AM UTC | 1 Agent replies | 2 Community replies | Feature Requests

Burp Porxy Features- Replay Request

Hi I would like to propose the following features in Burp. 1) Burp loads default profile:- Burp should allow users to specify the default template location. 2) Requests Replay :- We would like feed the requests...

Last updated: Jun 20, 2015 07:46AM UTC | 0 Agent replies | 0 Community replies | Feature Requests

Burp signed SSL certificates throw warning in Chrome

When burp generates CA-signed per-host certificates, Google Chrome marks these sites as having "Weak Security configuration (SHA-1 signatures), so your connections may not be private. Screenshot:...

Last updated: Jun 11, 2015 08:03AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

UI - Scanner:Results - tag resolved findings

Hi, I would love to be able to tag findings as 'already worked on and resolved' or 'read'. Helps in case I go through findings while the active scan is still on (reason being lack of time). In current state new findings are...

Last updated: Jun 10, 2015 11:23AM UTC | 1 Agent replies | 0 Community replies | Feature Requests

Page 62 of 64

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image