The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Choosing Issue types

Hello! I've a doubt about the scanning configuration, in Issues reported. Could you tell me if every scan type (passive, light etc) is independent of the rest? or are they incremental? I mean, if I select only "Medium...

Last updated: Apr 01, 2022 02:04PM UTC | 1 Agent replies | 0 Community replies | How do I?

Is it possible to use TLS passthrough for a specific directory path in a URL

Could you please tell me if it is possible to use TLS passthrough proxy option to pass through specific directories within a host domain? So that these directories would be passed through, but not others on the same host? ...

Last updated: Apr 01, 2022 01:34PM UTC | 2 Agent replies | 1 Community replies | How do I?

Targeted web cache poisoning using an unknown header

Hey, Can you have a look a this code because I can't get the lab resolved. I think I'm doing everything right but there's no way. Request ET / HTTP/1.1 Host:...

Last updated: Apr 01, 2022 10:33AM UTC | 2 Agent replies | 0 Community replies | How do I?

Unable to access labs

Hi Team, unable to access labs getting error: Apologies, the lab could not be started in a timely manner. Please try again or contact us if the problem persists.

Last updated: Apr 01, 2022 07:51AM UTC | 1 Agent replies | 0 Community replies | How do I?

Client certificate in Burp Enterprisemsts

Hi, Is there possibility to use Client TLS Certificate on Burp Enterprise, like in Proffesional and Community Edition? Thank you in advance and have a nice day!

Last updated: Mar 31, 2022 09:54PM UTC | 1 Agent replies | 1 Community replies | How do I?

Password authentication/modification

I'm having trouble logging in/changing my password. Every time I click 'forgot password' I get sent an email to retrieve my new hashed password at login. Once I'm logged on, I navigate to 'My Account' where it "should" allow...

Last updated: Mar 31, 2022 06:30PM UTC | 1 Agent replies | 0 Community replies | How do I?

Grep - Extract

I am learning to use burp suite and am interested in gathering some information through the Intruder function. Once I have set up the payloads (numbers, with rule to upper case) I go into the intruder options and add grep -...

Last updated: Mar 31, 2022 12:57PM UTC | 1 Agent replies | 0 Community replies | How do I?

Academy Labs

Hi, Just going through the labs and I don't seem to be able to complete the "Blind SQL injection with out-of-band data exfiltration" lab. I get a message "Client Error: Tampering with the _lab cookie (TrackingId) is not...

Last updated: Mar 31, 2022 12:11PM UTC | 1 Agent replies | 1 Community replies | How do I?

Allowing all hosts through SSL passthrough except one?

Any way to allow all hosts through SSL passthrough except one, say "hostname"? I tried this Regex: ^((?!hostname).)*$ Now everything passes through, but also including "hostname". I want hostname to *not*...

Last updated: Mar 31, 2022 08:03AM UTC | 6 Agent replies | 5 Community replies | How do I?

How to do a random number bruteforce in burp suite?

I want to do a bruteforce from number 38000000000 to 39000000000 but what is happening here, when I try to bruteforce with Payload type: Numbers it is giving a sequential bruteforce, what can happen here, what can I do to...

Last updated: Mar 31, 2022 07:44AM UTC | 1 Agent replies | 1 Community replies | How do I?

Unable to download Burp Suite

Hi, I’m not able to download the software. Tried it on chrome and Firefox. Every time I click the download button, it turns grey and shows downloading without downloading anything. Please help me out. Need this software...

Last updated: Mar 31, 2022 07:37AM UTC | 1 Agent replies | 0 Community replies | How do I?

Downloading does not complete

Hi , Cannot download Burp Suite Pro. I clicked on 'Download Software' option but nothing got downloaded even after half and hour. Only 'Downloading' message appears Please advise

Last updated: Mar 30, 2022 04:03PM UTC | 2 Agent replies | 2 Community replies | How do I?

Advanced Target Scope - Load File

Hey all, I normally used regex in advanced scope to make sure I capture all sub domains. However, I have a list of over 100 I'd like to check. I created a TXT file of the domains with regex but when I go to Load the file...

Last updated: Mar 30, 2022 09:52AM UTC | 6 Agent replies | 7 Community replies | How do I?

Lab: Exploiting XXE using external entities to retrieve files

Hello, i can't solve the Lab: Exploiting XXE using external entities to retrieve files, i am using body in request: ?xml version="1.0" encoding="UTF-8"?> <!doctype root [<!entity test system 'file: ///etc/passwd'>]>...

Last updated: Mar 29, 2022 09:24PM UTC | 1 Agent replies | 1 Community replies | How do I?

Burp scan crawler cannot detect or redirect a 307 status

I have a page: example.com . The login page is https://example.com/login After login it goes to http://example.com/my-details with a 307 internal redirect status and after that to https://example.com/my-details which is the...

Last updated: Mar 29, 2022 02:35PM UTC | 2 Agent replies | 2 Community replies | How do I?

Requested for Burp Suite Pro Free Trial but no update

Hi Team, I recently applied for a free trial on https://portswigger.net/burp/pro/trial. However, I have yet to receive the free trial license key.

Last updated: Mar 29, 2022 02:08PM UTC | 1 Agent replies | 0 Community replies | How do I?

getting error while clicking on access lab

Apologies, the lab could not be started in a timely manner. Please try again or contact us if the problem persists.

Last updated: Mar 29, 2022 09:36AM UTC | 1 Agent replies | 0 Community replies | How do I?

Import Client SSL Certificates

Hi, I was able to package my cert and key file into a PKCS#12 file and import it into "Project options -> SSL -> Client SSL certificates -> Override user options" from Burp UI. But I want to know if there is a way to load...

Last updated: Mar 29, 2022 08:13AM UTC | 1 Agent replies | 0 Community replies | How do I?

CSRF Lab token tied to non-session cookie. Set cookie via javascript?

Hello all, the solution for this lab used the fact that the search functionality could execute a set-cookie response header using another session id. I'm curious why could this not be done via javascript, prior to form...

Last updated: Mar 29, 2022 07:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Host header not present - Password reset poisoning via middleware

Hi, I'm trying to solve to complete the lab "Password reset poisoning via middleware". I sent POST /forgot-password to Repeater and add "X-Forwarded-Host:...

Last updated: Mar 29, 2022 07:57AM UTC | 2 Agent replies | 1 Community replies | How do I?

Page 124 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image