The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Sleep N seconds after calling macro

I want Burp to add a small pause between the macro and the repeater. In my case, I'm fetching a CSRF token and the web application refuses requests that are sent too quickly. How can I accomplish that?

Last updated: Mar 28, 2022 12:31PM UTC | 2 Agent replies | 0 Community replies | How do I?

Integration of Burp Suite Enterprise with any Vulnerability Management tool

Hi, I'm new to Burp Suite Enterprise and now I need to define which vulnerability management tool will I install in order to integrate scans from several different sources into one central location. From what I've been...

Last updated: Mar 28, 2022 11:27AM UTC | 1 Agent replies | 0 Community replies | How do I?

What is log?key=' in the cors tutorial ?

Hi, in this tutorial : https://portswigger.net/web-security/cors i saw this : var req = new XMLHttpRequest(); req.onload =...

Last updated: Mar 28, 2022 08:23AM UTC | 1 Agent replies | 0 Community replies | How do I?

Firefox Browser Doesn't Work Unless Burp Suite is on

Hello I recently installed and configured Burp Suite to use for Firefox and after setting up I realized I have a problem where now, unless Burp Suite is running with Intercept off I cannot access any websites through...

Last updated: Mar 28, 2022 07:38AM UTC | 2 Agent replies | 1 Community replies | How do I?

Trying to install certificate in Chromium-based Edge to test Edge extensions on Windows 11, getting HSTS errors

I've been attempting to install the Burp Suite certificate as instructed in the Chrome certificate installation guide, but I'm still getting HSTS errors on HTTPS websites. I don't know if I'm doing it wrong or if it's broken...

Last updated: Mar 26, 2022 12:57AM UTC | 1 Agent replies | 1 Community replies | How do I?

HTTP request smuggling, confirming a TE.CL vulnerability via differential responses

Hi I understood the principle of the lab and planned to test it. This lab environment should theoretically be TE.CL. First, I used this detection packet ...... Transfer-Encoding: chunked Content-Length:...

Last updated: Mar 25, 2022 11:48AM UTC | 2 Agent replies | 6 Community replies | How do I?

export websocket history

can I export websocket history as a single/multiple text file/files?

Last updated: Mar 24, 2022 09:36PM UTC | 3 Agent replies | 4 Community replies | How do I?

TLS Issue

Hello, I am receiving a TLS error (The server's certificate is not trusted) on a few sites that I am scanning. I have checked the dedicated server that hosts our Burp Suite Enterprise for what certs are located in the...

Last updated: Mar 24, 2022 04:35PM UTC | 1 Agent replies | 0 Community replies | How do I?

Host Header attacks

below are my request headers parameters to server as follows: Get /login HTTP/2 Host: actual-domain.com Host: fake1.com Host: fake2.com Cookie: xxxx . . . Host: fake3.com When I send the request using burp...

Last updated: Mar 24, 2022 03:00PM UTC | 2 Agent replies | 1 Community replies | How do I?

Cache-Control

if a web server uses : Cache-Control: no-store, no-cache, must-revalidate does that mean i should forget about cache poisoning?(i mean is that header and value mean this webserver does not support caches?)

Last updated: Mar 24, 2022 10:40AM UTC | 0 Agent replies | 0 Community replies | How do I?

proxy's problem

HI I had setting proxy 127.0.0.1:8080 and let browser also listen 127.0.0.1:8080, but when I request https://www.yahoo.com.tw , burpsiute event log apper "invalid client request received first line of request did not contain...

Last updated: Mar 24, 2022 06:49AM UTC | 1 Agent replies | 1 Community replies | How do I?

about chromium

Is the lower version of burp affected by cve-2021-21220?

Last updated: Mar 23, 2022 06:50PM UTC | 1 Agent replies | 0 Community replies | How do I?

vulnerabilities

how to solve vulnerabilities according to burp's scan result??

Last updated: Mar 23, 2022 01:31PM UTC | 1 Agent replies | 0 Community replies | How do I?

Scanning Atlassian Jira

We've been scanning Atlassian Jira for a few years now and it seems it gets more finnicky every time we upgrade Jira. Normally it would make 27,000+ requests, including Authenticating using our Macros, etc. No...

Last updated: Mar 23, 2022 01:22PM UTC | 5 Agent replies | 5 Community replies | How do I?

HTTP smuggling

Can you clarify that can an http smuggling attack begin with GET method?

Last updated: Mar 23, 2022 09:38AM UTC | 1 Agent replies | 0 Community replies | How do I?

Postman and Burp Suite pro Proxy error

Hi, I tried a new Postman collection which without the proxy configuration is valid means I get the expected responses in the Postman and configuration is well defined. I set the following configurations: Postman...

Last updated: Mar 22, 2022 01:29PM UTC | 2 Agent replies | 2 Community replies | How do I?

educational licence

Hello Burp Suite, I am a computer science student at the Goverment polytechnic koderma. I wanted to ask if it is possible to get a burp suite professional license for students. I really like to use your product but I...

Last updated: Mar 22, 2022 12:51PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burpsuite Collaborator Not Working (Using Public PortSwigger Server)

Hello everyone. I hope I am posting this in the correct channel. My question is regarding the Burpsuite Collaborator. My collaborator cannot connect to the Portswigger server and therefore does not work properly. Does anyone...

Last updated: Mar 22, 2022 11:57AM UTC | 5 Agent replies | 5 Community replies | How do I?

No more activations allowed for this licens

Hi, I get the error "No more activations allowed for this license" Please help me on this Product Burp Suite Professional License...

Last updated: Mar 22, 2022 07:43AM UTC | 1 Agent replies | 0 Community replies | How do I?

why there is an empty line after Content-Length header in http smuggle attacks?

for example : POST /search HTTP/1.1 Host: normal-website.com Content-Type: application/x-www-form-urlencoded Content-Length: 11 q=smuggling So the length of 'q=smugglingis' is 11. why there is an empty line...

Last updated: Mar 21, 2022 06:13PM UTC | 0 Agent replies | 1 Community replies | How do I?

Page 125 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image