Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
Perhaps this was already requested. If so, please ignore this request. I routinely save multiple proxy logs for the same application, depending on the type of test I'm conducting. At times I use several instances of Burp...
Automatic Backup is fantastic, it saved our work quite some time, when the Java environment decided to give up and crash. But, storing every time 700 megs, for example, in a state file, will fill up any hard drive over a...
Hi, it would nice to have an option to set prefix for automatic backup file name. When I am working on project1, I would like easy to set up prefix 'project1'. Then I can switch i.e. to project2...
Hi, Features The first one: it would be nice to be able to set an prefix or suffix to the auto backup file name. Already there is only time and this feature would help to distinguish between projects/sections. It...
It is tough to identify new extensions in the Bapp Store. It would be easy to identify new extensions if there was an additional column that listed the date updated. This would also be useful to identify extensions that were...
At the moment (and in the future) it would help during my testing that each set of credentials would have a tickbox next to them to enable or disable them. p.e. I use my basic authentication to login as admin, then log in...
Some of our client like to map issue to known standards. Is there anyway to correspond the vulnerability with OWASP top 10 number (if it relates to it).
The helpfulness of this payload when fuzzing a date/time parameter is automatic handling of the wrapping of values back to 1 when appropriate (i.e., avoid March 32nd). Extending the Dates payload with time components (down...
There are already a couple of requests to handle specific use cases of conditional Match and Replace that were declined -- and I have my own use case as well -- but I'd like to suggest a couple of generic options that could...
.
It would be nice if there was a permanent setting for "in future just copy and skip dialog." Bonus points for hotkeys for original/current session. Thanks for BSP...
Already posted here and then noticed, this is the new way to do it. http://forum.portswigger.net/thread/1686/force-update-check Current situation/problem: Burp only checks for new versions on startup. So when you can...
Every finding should be mapped to OWASP at a minimum. Every effort should be made to also map to WASC Threat Classification v2.0: http://projects.webappsec.org/w/page/13246978/Threat%20Classification
Scanner > Issue definition: Delete: Type index Add: Creation date Add: Modification date
I know there is logging available but this feature would be useful as another column
Potentially a web interface, so that it could sit on a test server as a stub, with the ability to inspect and reject packet history. The ability to only inspect the UI locally makes it limited in usefulness for sitting in...
I am using burp to check the security level of our web application. But my application usually checking referer header. If this header is changed, session will be time out. So, how do I test my web application except for...
Hi, I'm abend. Burp didn't start installing bapp store's item , because I mistook bad proxy setting. I want to output errorlog on Alerts tab that it can't install. regards
Currently the bit flipper payload can handle ASCII hex or literal values, but often I want to flip bits in a base64 payload. It would be super nice if this were built in!
using different projects and different Burp instances for each target. with one user license, on the same machine.
Page 65 of 68
Your source for help and advice on all things Burp-related.