Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
Hello, I'm trying to solve the 'Reflected XSS protected by very strict CSP, with dangling markup attack' Lab but am having some trouble with the collaborator. I put the following script into the exploit...
How do i add custom column to show referer header?
I want to reset all labs to restart my learning
I would like to know how i set this up so that it scans only the target URL and any subdommains it may find and anything else is not. As i keep getting other junk in the target tab such as facebook, google etc. I try remove...
Kindly i need assistance
I want to filter the scans by status and get the number of scan counts for particular date between or month wise. Is there any way to do in Burp enterprise portal or using Graphql API query.
https://0a5900c503a255e2c0a2ed1f02a7003c.web-security-academy.net/auth?client_id=bafv9dae8qp24om34rrbm&redirect_uri=https://0a0000a2035e554ec06eef8d00b00056.web-security-academy.net/oauth-callback/../post/next?path=https://ex...
can you reset the learning process? I want to start from beginning again
I found an interesting website with a JWT bypass vulnerability. It uses a simple secret key that can be discovered using brute force, which I did. However, I couldn't exploit the vulnerability because simply changing the id...
Every time I close Burp after saving, all my logs from Logger / Logger++ get erased. The only method that seems to work for me is if I manually export the logs to a CSV file. Is there a way to persist the logs after closing...
when I change the role id to 2 however i get an internal server error POST /my-account/change-email HTTP/2 Host: 0a5a007703e1b1f281891199006e0050.web-security-academy.net Cookie:...
How do i reset all my labs and progress to solve them again ?
Hello everyone, It's been 10 days since we paid for a license, but Portswigger still hasn't transmitted a license. We have contacted Portswigger 4 times by email, but they have never replied. We made a claim with...
I am running burp pro web app scan for a site by providing url and credentials using chrome extension but it seems burp is not injecting it's payload to attack surfaces that are there example search box after doing login and...
Does Burpsuite professional has the capability to scan Microservices? If yes, kindly provide some details on how to scan microservices.
Hi, I couldn't fully understand the phrase "As this will remain encoded server-side, it may go undetected until the browser decodes it again," written under the "Obfuscation via unicode escaping" section on the page...
As a burp suite enterprise user, I can easily test web apps. For testing APIs, how to create specific sites for methods such as POST, PUT, DELET and PATCH. How can we include JSON requests in these sites? We also use...
Hi, I just wanted to ask if I can still take the exam using my old voucher. I bought it quite a long ago, and when I tried to take the exam, I got this message on the Examity page: 'There are currently no exams...
Hi Team I would like ask about crawl .Katana software in Linux allow crawl and save links and endpoint to file . It is any way to save in Burp crawl website links to file .?
I'm not being able to open some sites like http://titan.picoctf.net:51160/ in burp browser. other sites using https works perfectly fine. Even this site works in my normal browser. But when I open in burpsuite I get error...
Page 19 of 332
Your source for help and advice on all things Burp-related.