Burp Suite User Forum
Does Burpsuite or any of its add ons support checks for NoSQL databases?
Would like to add this feature - where is a error - say network issue that has made the scan to stop - in that case, we would like to have a audible alert. This would help the user to focus his attention on other tasks...
Filter bypass options for the scanner would be useful. Just from a SQLi perspective, it would be great if I could have radio buttons that could enable SQLmap tamper script style payload modification options such as...
I hope it doesn't take much work to add this feature to the current version. It would really be helpful if you can just right click on any parameter and add them to the exclude list of scanner rather than doing a copy and...
I would like to ask for a feature that would allow me to choose a maximum file size for each log type(much like what i do with tshark for packet capturing). This would force burp to create a new log file everytime the file...
Hi Burp Team, Good day! We have been using active scanner in our CI builds on a regular basis. However, sometime active scan queue items get stuck/slow/become stale and they appear to make little to no progress for a...
Hi, It would be nice to add to the "Match and Replace" feature of the Proxy Options the possibility to not only add and replace but to encode, or even do the same as with the intruder payload processing (adding rules in a...
Some applications offer a large set of sites that only present different data but are based on the same template. This can result in thousands of pages in the scope that are basically irrelevant. There should be some way...
When I assess the JSON type request, intruder put the add position like below: testparameter=${"user":"admin","password": "password00"}$ I would like to put the target position like...
When running an attack with intruder, particularly a Sniper attack with number payload, it would be good if in the Payload field, the base request (request ID 0) displayed what the contents were between the $$ symbols. At...
Can you add the ability to: a) Do things without confirmation if I so want? Clear History for example, close Burp for another. And generally do think of other common tasks and add the ability to do things with keyboard...
Perhaps this was already requested. If so, please ignore this request. I routinely save multiple proxy logs for the same application, depending on the type of test I'm conducting. At times I use several instances of Burp...
Automatic Backup is fantastic, it saved our work quite some time, when the Java environment decided to give up and crash. But, storing every time 700 megs, for example, in a state file, will fill up any hard drive over a...
Hi, it would nice to have an option to set prefix for automatic backup file name. When I am working on project1, I would like easy to set up prefix 'project1'. Then I can switch i.e. to project2...
Hi, Features The first one: it would be nice to be able to set an prefix or suffix to the auto backup file name. Already there is only time and this feature would help to distinguish between projects/sections. It...
It is tough to identify new extensions in the Bapp Store. It would be easy to identify new extensions if there was an additional column that listed the date updated. This would also be useful to identify extensions that were...
At the moment (and in the future) it would help during my testing that each set of credentials would have a tickbox next to them to enable or disable them. p.e. I use my basic authentication to login as admin, then log in...
Some of our client like to map issue to known standards. Is there anyway to correspond the vulnerability with OWASP top 10 number (if it relates to it).
The helpfulness of this payload when fuzzing a date/time parameter is automatic handling of the wrapping of values back to 1 when appropriate (i.e., avoid March 32nd). Extending the Dates payload with time components (down...
There are already a couple of requests to handle specific use cases of conditional Match and Replace that were declined -- and I have my own use case as well -- but I'd like to suggest a couple of generic options that could...
Page 64 of 68
Your source for help and advice on all things Burp-related.