The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

HTTP request tunnelling

In this tutorial(HTTP request tunnelling) : https://portswigger.net/web-security/request-smuggling/advanced/request-tunnelling should we setup a proxy server in burp suite from user options to tunnel the http requests?

Last updated: Feb 09, 2022 08:17AM UTC | 1 Agent replies | 0 Community replies | How do I?

Proxy with BurpSuite Enterprise

I'm trying to launch my BurpSuite agent with port 8090 opened for me to be able to proxy traffic through it and then run a Scan. Is this possible with BurpSuite Enterprise? Use-Case Example: I launch a burp agent with...

Last updated: Feb 08, 2022 09:11AM UTC | 6 Agent replies | 5 Community replies | How do I?

Authentication bypass via encryption oracle

I'm stuck in "Re-encode the data and copy the result into the notification cookie of the decrypt request. When you send the request, observe that an error message indicates that a block-based encryption algorithm is used"...

Last updated: Feb 07, 2022 08:39PM UTC | 3 Agent replies | 2 Community replies | How do I?

Installation of BurpSuite Professional

I was wondering if anyone knows what to do to fix the proxy host and port if BurpSuite Pro with a license is installed manually and is not set up with the host address or the port? My trial license expired so have to...

Last updated: Feb 07, 2022 06:05PM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab problem solving related help

Actually I deleted the account mistakenly and now i can't login to my account in basic click jacking lab.☹ So i can't solve the lab. Please help me to solve the problem. Is there any way to bring up the credentials back...

Last updated: Feb 07, 2022 04:23PM UTC | 1 Agent replies | 0 Community replies | How do I?

remove cookie parameter from Burp suite Match and Replace

I am trying to remove unnecessary google and facebook cookies in my application request, i've tried Match: (cookie=[^;]+); Replace: but didnt work

Last updated: Feb 07, 2022 01:33PM UTC | 4 Agent replies | 3 Community replies | How do I?

burp suite not oprning on my pc

i downloaded the burp from the site today and installed, i also installed java latest version from oracle and whenever i launch the burp file it starts install wizard after installing nothing comes up... i need help please

Last updated: Feb 07, 2022 08:56AM UTC | 1 Agent replies | 0 Community replies | How do I?

reset my lab

hello admin! Could you please reset my lab? i am doing demo in my class but i cant reset to do again. thanks

Last updated: Feb 07, 2022 08:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

same issue with me as well

can you please help me ASAP

Last updated: Feb 04, 2022 04:18PM UTC | 1 Agent replies | 1 Community replies | How do I?

Didn't got trial Burp Suite Proffesional Licence Key.

I have Filled the form for demo Burp Suite Proffesional, Also downloaded the software,didn't got the key yet. Please see into it.

Last updated: Feb 04, 2022 11:45AM UTC | 1 Agent replies | 0 Community replies | How do I?

Scanning subdirectories

If I want to only audit https://xx.com/subfolder how would I accomplish this? Right now I'm crawling xx.com, then auditing the subfolder when it shows up in the crawl, but sure there's a way to just start off with the...

Last updated: Feb 04, 2022 09:35AM UTC | 1 Agent replies | 0 Community replies | How do I?

License key wasn't accepted after reinstall

Hi team.. I installed Burp Enterprise on one server and it was working fine. I tried to scan our web application (with login and password) and Burp Log showed error "libatk-1.0.so.0" (same problem from post "Unable to...

Last updated: Feb 04, 2022 08:37AM UTC | 1 Agent replies | 0 Community replies | How do I?

Issues with 'Blind SQL injection with out-of-band interaction' Lab

Hello PortSwigger Team, It seems that the recommended solution is not working correctly for me. I do currently have the professional edition of the Burp Suite and I am replacing the...

Last updated: Feb 03, 2022 08:48PM UTC | 2 Agent replies | 3 Community replies | How do I?

Create a new Object for burp.IHttpRequestResponse

Hi Team, One of my requirement is to add sitemap with a given byte[] request and byte[] response. I have tried calling the below method. IBurpExtenderCallbacks.getCallbacks().addToSiteMap(httpRequestResponse); I have...

Last updated: Feb 03, 2022 11:56AM UTC | 2 Agent replies | 2 Community replies | How do I?

Burp Enterprise licensing when I need to tear down and rebuild Enterprise & Agent servers

Hi Team. We have a requirement to tear down and spin up new servers in our environment on a scheduled basis. How does Burp Enterprise licensing work in this case? Do I need to re-apply existing licenses on my Enterprise &...

Last updated: Feb 03, 2022 09:54AM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab Not Responding

Http Request muggling Lab 2 reeturns error when ent the smuggling request. The Response is: HTTP/1.1 400 Bad Request Content-Type: application/json; charset=utf-8 X-Content-Type-Options: nosniff Connection:...

Last updated: Feb 03, 2022 09:11AM UTC | 7 Agent replies | 8 Community replies | How do I?

Burp professional - updates and BApp store not working - proxy

Hi, We have a challenge with updating the Burp suite professional and connecting to BApp store. Our machines are behind corporate proxy with SSL inspection turned on, do this cause a problem with the updates and connecting...

Last updated: Feb 02, 2022 01:17PM UTC | 2 Agent replies | 1 Community replies | How do I?

cross site scripting (dom)

hi there burp is giving me this Issue detail The application may be vulnerable to DOM-based cross-site scripting. Data is read from window.location.pathname and passed to the 'append()' function of JQuery. Issue...

Last updated: Feb 02, 2022 11:54AM UTC | 1 Agent replies | 0 Community replies | How do I?

how do we calculate value for tranfer encoding??

POST / HTTP/1.1 Host: your-lab-id.web-security-academy.net Content-length: 4 Transfer-Encoding: chunked 87 GET /admin/delete?username=carlos HTTP/1.1 Host: localhost Content-Type:...

Last updated: Feb 02, 2022 11:53AM UTC | 2 Agent replies | 2 Community replies | How do I?

New Users Access Issues

Hi, I have administrator access for Burp Suite Enterprise, I have created new user account for my team members and gave them administrator access in Burp Suite Enterprise, users received the email with the password link,...

Last updated: Feb 02, 2022 10:04AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 133 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image