Burp Suite User Forum

Create new post

Reset labs progress

Hi there, Can you please reset my training labs progress? I'd like to be able to start again from scratch

Last updated: Sep 19, 2024 06:21AM UTC | 1 Agent replies | 0 Community replies | How do I?

How do I turn off extension auto-highlighting?

this might be a very dumb question, but when using an extension which performs auto highlighting in the proxy tab, how can i turn that off? for example - JWT Editor, an otherwise wonderful piece of software, highlights...

Last updated: Sep 19, 2024 03:15AM UTC | 0 Agent replies | 0 Community replies | How do I?

Client-side prototype pollution in third-party libraries

Hi, I'm having trouble with the lab, after I exploited the vulnerability and tested It on myself the XSS fired with alert(1) but when I tried alert(document.cookie) the cookies didn't appear and there's no attribute prevent...

Last updated: Sep 18, 2024 09:50PM UTC | 1 Agent replies | 2 Community replies | How do I?

Zscaler blocking the burp suite interactions

Hi Team, We are facing the issue that Zscaler is blocking the burp suite interactions like being unable to add extensions and use collaborators. On troubleshooting this issue we observe this seems to be an SSL issue, Burp...

Last updated: Sep 18, 2024 02:50PM UTC | 3 Agent replies | 3 Community replies | How do I?

Hitting ERR_BLOCKED_BY_ORB when trying to intercept my local server

I'm currently using Burp Suite Community Edition, and im Hitting ERR_BLOCKED_BY_ORB on some of my .js request when trying to load my application then the page just become blank. I would greatly appreciate any help or advice...

Last updated: Sep 18, 2024 01:34PM UTC | 2 Agent replies | 3 Community replies | How do I?

Question about OAuth account hijacking via redirect_uri

I was working on this lab, when i found, when you send the malformed request i mean the redirect_uri value --> it immediately sends back you the token --> my Question is should i assume that the lab is skipping the...

Last updated: Sep 18, 2024 01:20PM UTC | 0 Agent replies | 0 Community replies | How do I?

Issue with port swigger lab HTTP request smuggling

I am trying to solve this lab but every time the same error pops up that is "Read Timeout". I have tried everything but the error is still there. Can you please help with this. Here are the images of request...

Last updated: Sep 18, 2024 07:29AM UTC | 1 Agent replies | 0 Community replies | How do I?

Getting Inconsistent Results when running Lab: Username enumeration via different responses

Hi team, I am running the Authentication Lab with Burp Suite inside Kali Linux on top of Virtual Box and when I open Burp I use the built-in Chromium browser.Wwhen I run the intruder attack using Sniper, Single...

Last updated: Sep 18, 2024 06:34AM UTC | 1 Agent replies | 0 Community replies | How do I?

Academy Progress Reset

Hello :) Can you please reset my progress on the labs and learning materials?

Last updated: Sep 17, 2024 04:41PM UTC | 29 Agent replies | 34 Community replies | How do I?

Intercept On not working

hello, Did something change with the newest release of Burp Pro v2024.7.0? when I turn on intercept, and capture the request. I see the same request repeating every 5 seconds. e.g.; 14:40:25 13 Sep 2024 HTTP ->...

Last updated: Sep 17, 2024 01:07PM UTC | 1 Agent replies | 0 Community replies | How do I?

Automated scan through Keycloack

Hello, Using BurpSuite professional, i want to perform automated scanning on an application that has no authentication mechanism. They use keycloak instead so that people can authenticate. The problem is, BurpSuite...

Last updated: Sep 17, 2024 12:46PM UTC | 1 Agent replies | 0 Community replies | How do I?

Getting different results on each and every scan for same site

Team, We are facing an issue with scan results, I am scanning same site with configuration Crawl & Audit - Deep from the library and on every scan there is huge difference in the audit items as well as the results. I m...

Last updated: Sep 17, 2024 12:12PM UTC | 1 Agent replies | 1 Community replies | How do I?

How do I stop burpcollaborator hitting my site?

I am running some servers for personal use and have never used burp suite or any of your tools. But my nginx logs are showing loads of hits with burpcollaborator.net in the UA I've blocked the IP they are coming from with...

Last updated: Sep 17, 2024 11:05AM UTC | 1 Agent replies | 2 Community replies | How do I?

How to reset a lab

Hello Support, I was trying the "Lab: Basic clickjacking with CSRF token protection" but I tried to intercept server response and changed the post for change email with delete account. Now I'm unable to login using the...

Last updated: Sep 17, 2024 08:16AM UTC | 17 Agent replies | 20 Community replies | How do I?

Reset all labs

How do I reset all my labs

Last updated: Sep 17, 2024 07:15AM UTC | 1 Agent replies | 0 Community replies | How do I?

I want to remove my existing activation of Burp Suite Professional License

I want to remove my existing activation of Burp Suite Professional License. We've reinstalled OS on 4 of our systems and we would like to remove our existing license and re-activate on the new system. I opened Burp and...

Last updated: Sep 16, 2024 07:49AM UTC | 2 Agent replies | 1 Community replies | How do I?

How to reset my password to a custom password

If i give reset password, i am getting an email and it gives a passwords. Can i change password to something i can remember?

Last updated: Sep 15, 2024 10:45PM UTC | 2 Agent replies | 4 Community replies | How do I?

IMPORT .BURP TO BURP ENTERPRISE

Hello everyone, In my environment i have 2 solutions of Burp (Professional and Enterprise), and i have a question. Is possible to import the .burp file project (generated by Burp Professional) to my Burp Enterprise to...

Last updated: Sep 13, 2024 12:23PM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab #5: CSRF where token is tied to non-session cookie & Lab #6: CSRF where token is duplicated in cookie issues

Hello, I have been working on the CSRF Labs and I'm having problem with the following labs: - Lab #5: CSRF where token is tied to non-session cookie - Lab #6: CSRF where token is duplicated in cookie issues For Lab...

Last updated: Sep 13, 2024 11:30AM UTC | 6 Agent replies | 11 Community replies | How do I?

Lab: URL-based access control can be circumvented

I just have a question about the terminology used in the lab. "This website has an unauthenticated admin panel at /admin, but a front-end system has been configured to block external access to that path. However, the...

Last updated: Sep 13, 2024 07:42AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 1 of 327

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image