Burp Suite User Forum

Create new post

Bruteforce authentication forms

Hello everyone! I test the scanner and scan http://webscantest.com/login.php This form has a simple password - admin / admin However, burp did not find this vulnerability (and other scanners easily find it) Why is...

Last updated: Dec 02, 2021 02:32PM UTC | 1 Agent replies | 1 Community replies | How do I?

Modify target from abc to xyz

Suppose I have abc.com and xyz.com both are different versions of a same application. And I want to run all the tests I did on abc.com on xyz.com, Is it possible in Burpsuite to just edit the url from abc to xyz and change...

Last updated: Dec 02, 2021 12:21PM UTC | 1 Agent replies | 0 Community replies | How do I?

hi I need a little bit help

hi, I want to place an automated order or place an order headlessly. I tried a lot but I am not able to figure it out it would be great if u help me.

Last updated: Dec 02, 2021 09:32AM UTC | 1 Agent replies | 0 Community replies | How do I?

Intercepting AVD-Emulated Android 11 Using Macbook Pro M1 Burp

Does anyone has any experience with this before? I cant seem to install the Burp certificate on the device since the Android 11, and the only Android version available in Mac is only for Android 11.. I know that this is not...

Last updated: Dec 02, 2021 08:23AM UTC | 1 Agent replies | 0 Community replies | How do I?

ProjectDiscovery vi Burp

Hi Team I have stupid question .I'm not smart person .If I will ask your Burp Team that way .Why is better to use.?? BURP Professional($$$) or all this software from ProjectDiscovery...

Last updated: Dec 01, 2021 02:40PM UTC | 2 Agent replies | 1 Community replies | How do I?

Instalation of Burp Suite

When I've been hasked to enter Licence Key I select the Licence Key file in the location the licence number appers in the window when i click next .... the number disapear and I stay in the same windows ... (like not a...

Last updated: Dec 01, 2021 09:44AM UTC | 1 Agent replies | 0 Community replies | How do I?

Run a BURP scan without error

After setting up a scan for a Fax portal, I'm getting prompted for credentials, even though I have defined these in the scan. When I input the same credentials when browsing the webpage to be scanned, I receive the error:...

Last updated: Nov 30, 2021 09:19PM UTC | 4 Agent replies | 6 Community replies | How do I?

Is it possible to configured Burp Enterprise to use a Burp Collaborator server?

One of my colleagues has asked if it it possible to configured Burp Enterprise to use our own Burp Collaborator server? I've had a quick poke around the scan and server settings, as well as your online documentation but...

Last updated: Nov 30, 2021 06:23PM UTC | 1 Agent replies | 0 Community replies | How do I?

BurpSuite Enterprise Edition + Docker Integration + C# REST.API PARSER

I am working with a team on the following stuff: - C# REST.API SCAN PARSER WHICH CREATES SCANS OF AN EXISTING SITE AND EXECUTES SCANS AND DISPLAYS THE REPORT WITH A JSON PARSER - Dockerfile including the installation of...

Last updated: Nov 30, 2021 03:45PM UTC | 1 Agent replies | 0 Community replies | How do I?

"Open browser" missing

I don't find the "open browser" under Proxy > Intercept https://ibb.co/jwrJCXh

Last updated: Nov 30, 2021 02:53PM UTC | 1 Agent replies | 1 Community replies | How do I?

run burp on openjdk 17

When I try to run burp Use this command java -jar -Xmx4g burpsuite_pro_v2021.10.2.jar Error To run Burp Suite using Java 17+, please supply the following JVM...

Last updated: Nov 30, 2021 01:43PM UTC | 1 Agent replies | 0 Community replies | How do I?

Where did the mac edition go?

I can't seem to find the macOS version for the BurpSuite community edition. Please help.

Last updated: Nov 30, 2021 08:33AM UTC | 1 Agent replies | 0 Community replies | How do I?

LAB: Exploiting HTTP request smuggling to reveal front-end request rewriting

Hello, I have followed everything exactly as written in the tutorial and in the video. At the end of the video Michael Sommer says "the lab is solved", but it isn't and has to keep trying and trying for two minutes and...

Last updated: Nov 29, 2021 08:07PM UTC | 1 Agent replies | 2 Community replies | How do I?

Automated Scan and Auditing of REST API

Hi, We want to scan and audit our REST APIs (The endpoints we have needs to be provided with 2-4 headers) and invoke this scan using the native rest API. Is this possible? [because we did not find any way to configure any...

Last updated: Nov 29, 2021 04:22PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burpsuite on Kali = blank window

Running kali rolling release 2021.4. When I start burpsuite either using the GUI or command line java -jar /usr/share/burpsuite/burpsuite.jar it starts, shows the startup window, and then goes to a blank window. Trying...

Last updated: Nov 29, 2021 04:16PM UTC | 1 Agent replies | 1 Community replies | How do I?

Lab: Username enumeration via response timing - ("X-Forwarded-For:" not working)

Hi, the "X-Forwarded-For:" header is not working, I tried to do lot of researches but no luck. Below are the request and response. Tried placing above and below connection still did not work. Please help, Thanks in...

Last updated: Nov 29, 2021 12:00PM UTC | 3 Agent replies | 3 Community replies | How do I?

Use NTLMv2 platform authentication with the Scanner?

Hi, I am targetting a website that uses NTLMv2. I have successfully configured the authentication in the project options (have also tried user options) and can browse the website fine - as well as use the repeater for...

Last updated: Nov 29, 2021 11:58AM UTC | 9 Agent replies | 8 Community replies | How do I?

Do not want to manually forward each request

Hi, I am trying to leverage Burp proxy to obtain the API calls in our custom web application. I have a series of automated tests that I would like to run while Burp is running to obtain a list of the POST APIs with their...

Last updated: Nov 29, 2021 10:05AM UTC | 2 Agent replies | 1 Community replies | How do I?

Exam Registration Issue: "You are not enrolled in any courses with current or upcoming exams."

Hi PortSwigger. I registered for the Burp Suite exam, i received the confirmation email for the exam purchase. I also created an account in examity as per portswigger instructions mentioned in the email that I received...

Last updated: Nov 29, 2021 08:46AM UTC | 1 Agent replies | 0 Community replies | How do I?

Blind SQLi using Time delays

Hi there! I was solving the lab where trackingID cookie is vulnerable to blind sql injection and one has to cause time delay of 10 secs. My question is this why do we have to concatenate our payload '|| (SELECT...

Last updated: Nov 29, 2021 07:54AM UTC | 0 Agent replies | 2 Community replies | How do I?

Page 120 of 311

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image