The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

LAB: Exploiting HTTP request smuggling to perform web cache poisoning

Hello everyone! Im having troubles with this lab. I tried even to follow the youtube videos to get with the solution and not even that helps. Im getting a 400 and {"error":"Invalid request"} I tried also to switch...

Last updated: Dec 23, 2021 12:43AM UTC | 4 Agent replies | 5 Community replies | How do I?

Digest Auth in Burp was removed?

Hi, What happened with Digest authentication support? https://portswigger.net/burp/documentation/desktop/options/connections "Supported authentication types are: basic, NTLMv1, and NTLMv2" In the previous versions...

Last updated: Dec 22, 2021 12:18PM UTC | 4 Agent replies | 5 Community replies | How do I?

Any Solution to "Network Protocol Error" in Firefox while Using Burp!

Hi Guys, I've been seeing an error on some websites while using burp the error on firefox goes like --- Network Protocol Error An error occurred during a connection to target.com. The page you are trying to...

Last updated: Dec 22, 2021 11:31AM UTC | 1 Agent replies | 0 Community replies | How do I?

scanning ip ranges ?

Hello, given we have set of ip ranges to scan. how i can do with burp to set different ip ranges in the target scope ? can someone advise ?

Last updated: Dec 22, 2021 08:18AM UTC | 1 Agent replies | 0 Community replies | How do I?

Find and replace with $ sign in replace not working

I am attempting to use find and replace to replace the user agent string with a jndi payload. However the dollar sign in the replacement string causes the replacement not to work. For instance: Match:...

Last updated: Dec 21, 2021 07:19PM UTC | 2 Agent replies | 2 Community replies | How do I?

Stop scan

I need to stop scan on paticular GET/POST keyword. If web page says: "Error. Could not find..." I want previous GET/POST. To stop at that message.

Last updated: Dec 21, 2021 10:44AM UTC | 4 Agent replies | 3 Community replies | How do I?

Upgrade Burp Enterprise, Linux Distro

Would anyone have a link to detail the steps in upgrading Enterprise Edition within a Linux environment? My current version is; 2021.12.1-8680, Java version: 11.0.10 Any advice appreciated.

Last updated: Dec 21, 2021 10:02AM UTC | 1 Agent replies | 0 Community replies | How do I?

GraphQL mutation for extensions

Does graphql support mutations of a given site to add an extension?

Last updated: Dec 21, 2021 09:13AM UTC | 1 Agent replies | 0 Community replies | How do I?

Can my employer purchase the exam for me?

How can my employer purchase the exam for me? Don't you have something like a voucher system or can you email us a quotation?

Last updated: Dec 21, 2021 08:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Cannot access the web security lab

I can not access any lab on your website using Microsoft Edge. When i click "Access the lab", it shows the error message is "ERR_CONNECTION_TIMED_OUT". I tried another device and browser but they have the same issue. Can...

Last updated: Dec 21, 2021 08:12AM UTC | 2 Agent replies | 2 Community replies | How do I?

plaintext password

Hi there, if I capture a login request and view a password in plaintext form, would this indicate a vulnerability? Considering that if you capture it in some applications like facebook it will appear encrypted.

Last updated: Dec 20, 2021 02:19PM UTC | 1 Agent replies | 0 Community replies | How do I?

Scan DIV class

Hi! I need to scan just a part of web page - DIV class. This class is changing time to time, and I want to find how and when it changes. It shoud be random, but I don't think it is. For example, clock on web page changes...

Last updated: Dec 20, 2021 01:40PM UTC | 2 Agent replies | 2 Community replies | How do I?

Burp Pro isn't intercepting HTTP requests from Terminal

Hello, I am using Burp Pro and it doesn't intercept any HTTP request from Terminal on my macOS. Help me, please. Thank you.

Last updated: Dec 20, 2021 11:54AM UTC | 1 Agent replies | 0 Community replies | How do I?

Why simple quote is necessary in SQL Blind Injection using TrackingID?

I'm in first lab of Blindd SQL Injection and payload for test is: TrackingId=xyz' AND '1'='1 Why is necessary this quotes in '1' and '1?

Last updated: Dec 17, 2021 02:51PM UTC | 1 Agent replies | 0 Community replies | How do I?

Questions about licensing

Hi. Please let me know about the license of Burp Suite. I am aware that the Burp Suite license is to be installed on the device after purchase, but do I register an account with the user of the license? Since the user...

Last updated: Dec 17, 2021 11:11AM UTC | 2 Agent replies | 1 Community replies | How do I?

Would Burp Suite Professional detect log4j vulnerability?

We use Burp Suite Professional for regular scans of our application. Is there a guarantee that the scan tests for the log4j vulnerability?

Last updated: Dec 17, 2021 08:45AM UTC | 1 Agent replies | 0 Community replies | How do I?

Burpsuite Enterprise uninstall script?

What is the usage for uninstall script at /usr/local/burpsuite_enterprise/? It asks to run as root but I would need to know the required params and command to run it silently as root.

Last updated: Dec 16, 2021 06:20PM UTC | 1 Agent replies | 0 Community replies | How do I?

Configure Burp to Intercept/Retrieve/Store Streaming Responses

Hello everyone! So basically one web application which i'm currently testing seems to be using some kind of Streaming Response technology, and i'm not being able to configure Burp to be "compatible" with that. I can...

Last updated: Dec 16, 2021 09:17AM UTC | 2 Agent replies | 1 Community replies | How do I?

log4j2 vulnerability - are burpesuite products affected?

Hi, Could you please clarify if burpesuite products are affected by newly discovered log4j vulnerability. More info on the vulnerability...

Last updated: Dec 16, 2021 08:14AM UTC | 3 Agent replies | 2 Community replies | How do I?

Remove Java JRE 1.9.0_4 on Burp Suite Enterprise Edition v2021.11

How do we remove / clean up the following unsupported JAVA JRE within Burp Suite Enterprise installation ? : The following Java JRE installation is unsupported : Path :...

Last updated: Dec 15, 2021 04:01PM UTC | 2 Agent replies | 1 Community replies | How do I?

Page 139 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image