The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scan App with a remember my browser login option

The application I'm attempting to scan has two options for authentication: 1. Remember my browser (after mfa code has been sent via email) 2. MFA everytime you login My scans are not able to make it past this step to...

Last updated: Jul 19, 2024 09:29PM UTC | 1 Agent replies | 1 Community replies | How do I?

Your JRE appears to be version 17.0.12-ea from Debian - error

hi every time i'm geting this massage error... was looking for a sulotion for an hour now and still can't find the solution the message is: Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on...

Last updated: Jul 19, 2024 12:25PM UTC | 1 Agent replies | 0 Community replies | How do I?

reset all my labs and progress.

hi. could you reset all my labs and progress.I confirm. Thanks

Last updated: Jul 19, 2024 07:37AM UTC | 1 Agent replies | 0 Community replies | How do I?

Asymmetric encryption of payload

Hi there, I would like to ask about the situation where the client server and the server have their own set of public and private keys for key exchanges. So, what happens is the both the request and the response will be...

Last updated: Jul 18, 2024 04:14PM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab: Offline password cracking

Hi All im Trying To Solve This Lab : Lab: Offline password cracking i know that i need to use xss vulnrability to steal carlos cookie but when i put a script it only reflect and show My cookie what i should do to...

Last updated: Jul 18, 2024 12:26PM UTC | 2 Agent replies | 1 Community replies | How do I?

Active scan checking for categories outside of selected issue categories

Hello, Firstly, can't thank you folks enough for this awesome tool. I am trying to play around with the active scan under the "Issues Reported" section of the configuration. I have created a custom configuration in my...

Last updated: Jul 18, 2024 12:06PM UTC | 2 Agent replies | 1 Community replies | How do I?

Web Cache Poisoning with an Unkeyed Header

I solved the "Web Cache Poisoning with an Unkeyed Header" lab using the Exploit server provided in the lab. However, when I try to solve it a second time with my own exploit server that I set up with Ngrok and Python, it...

Last updated: Jul 18, 2024 07:46AM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab: SameSite Lax bypass via cookie refresh -

I was thinking about this part: "Observe that, after a pause, the CSRF attack is still launched. However, this is only successful if it has been less than two minutes since your cookie was set. If not, the attack fails...

Last updated: Jul 17, 2024 08:30PM UTC | 0 Agent replies | 0 Community replies | How do I?

Flipping bit Attack and Character Frobber

I was wondering if you could share with me how I could effectively perform a Flipping bit attack and Character robbery by using the Burp suite to uncover an encrypted base attack in the application that impacts the...

Last updated: Jul 17, 2024 04:04PM UTC | 1 Agent replies | 0 Community replies | How do I?

Can not activate Burp Suite Pro

Hi Burp Suite Support, I have issue with activation of Burp Suite Pro. I got message "No more activations allowed for this license". Could you please help me out? Thanks,

Last updated: Jul 16, 2024 10:05AM UTC | 1 Agent replies | 0 Community replies | How do I?

FIX: Burpsuite not using full resolution

Hello,I am having issues with Burp suite only using 1024x768 of the screen instead of full 1080p. It opens in full screen but all the content is in the up left corner OS: BlackArch with dwm window manager on a KVM/QEMU...

Last updated: Jul 15, 2024 09:03PM UTC | 3 Agent replies | 3 Community replies | How do I?

multistep clickjacking

<style> iframe { position:relative; width: 500px; height: 700px; opacity: 0.0001; z-index: 2; } .firstClick, .secondClick { position:absolute; top:410px; ...

Last updated: Jul 15, 2024 12:45PM UTC | 4 Agent replies | 3 Community replies | How do I?

Auditing: Ignored Insertion Points: Skip all tests for there parameters

Hi, I defined my own configuration as follow: Settings\Configuration library New > Auditing Ignored Insertion Points: Skip all tests for there parameters How can I skip from auditing when scanning these URL path and...

Last updated: Jul 15, 2024 12:08PM UTC | 4 Agent replies | 3 Community replies | How do I?

CSRF Poc Doesn't work in Portswigger's Labs.

Hi, I've done some labs in the Academeny and I some are easy to understand and solve, However, the CSRF section doesn't work for me. I have created PoC for the First CSRF Lab titled: "CSRF vulnerability with no...

Last updated: Jul 15, 2024 10:13AM UTC | 2 Agent replies | 3 Community replies | How do I?

Collect Training Progress for Engineers

Hi there, I have a handful of engineers using this platform to train and I'd love to track their progress. Is there an API I could use to track their progress? thanks! Damien

Last updated: Jul 15, 2024 08:08AM UTC | 1 Agent replies | 0 Community replies | How do I?

Academy Lab "Reflected XSS in canonical link tag" will not marked solved

Hi, i made my own solution for solving the Lab: `https://[web-academy]/post?postId=4&test=2%27accesskey=%27X%27onclick=%27javascript:alert(1)` and it does not work. Also the official answer does not work for me. But both...

Last updated: Jul 15, 2024 07:55AM UTC | 2 Agent replies | 1 Community replies | How do I?

Burp Suite Pro License can be used for more than one machine?

Hi Burp Suite Team, Can you give clarification for this question i got. If I have 2 laptops, one is Macbook, one is Windows laptop, can I install Burp Suite Pro for these 2 devices with one Burp Suite Pro license, or...

Last updated: Jul 13, 2024 08:36PM UTC | 1 Agent replies | 1 Community replies | How do I?

error

Couldn't read the API definition. Review the definition and correct any syntax errors. the error is displayed when i try for api scan and not working aslo

Last updated: Jul 12, 2024 01:10PM UTC | 1 Agent replies | 0 Community replies | How do I?

Confirming Client-Side Desync Results in Burp Scan Report

I ran a BURP scan and the client-side desync was detected. I'm having trouble understanding the confirmation logic in a Burp Scan report. I have read the James Kettle article as well as performed the Portswigger lab for the...

Last updated: Jul 12, 2024 01:04PM UTC | 2 Agent replies | 1 Community replies | How do I?

How to View Response in Repeater?

I took a short course on using Burp and wanted to play around with it some more a few days later. However, I noticed that when I capture an HTTP response and try to send it to Repeater, I can only see the request there. I...

Last updated: Jul 12, 2024 09:49AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 16 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image