The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Reset my Burp License

I am getting an error like 'Too many activations' My test machine was down so I used a temporary laptop. Now that my main server is running I want to return the license to that machine but Burp Pro says too many...

Last updated: Feb 15, 2021 08:37AM UTC | 1 Agent replies | 0 Community replies | How do I?

Intercepting Android version 8.1 HTTPS Traffic

Hi there, I have a rooted Nexus 5x (Magisk rooted) with Android 8.1 installed. I have been trying to intercept traffic with Burp but I'm running into problems that I have never had before. There are only a few HTTPS...

Last updated: Feb 13, 2021 12:43PM UTC | 5 Agent replies | 8 Community replies | How do I?

Lab: SSRF via OIDC dynamic registration

Can anyone explain how would one come by the "http://169.254.169.254/latest/meta-data/iam/security-credentials/admin/" endpoint as it appears in the lab solution? My understanding is that it is an IP that is within reach of...

Last updated: Feb 12, 2021 07:10PM UTC | 0 Agent replies | 0 Community replies | How do I?

how do i understand that which parameter is vulnerable ?

I am working with the burp hint and solution to exploit vulnerabilities .In many of these there are some parameters that are vulnerable and we change the values usually given to alpha numeric so then the vulnerability...

Last updated: Feb 12, 2021 04:12PM UTC | 1 Agent replies | 0 Community replies | How do I?

how to use "Match and replace" feature

Hi team, i just loved burpsuit and am using free version of burp and i need some help to understand some feature. there is match and replace feature, i need help :- how can i put value of every parameter during...

Last updated: Feb 12, 2021 12:28PM UTC | 1 Agent replies | 0 Community replies | How do I?

Unable to capture requests with Pulse Secure running

I have a mobile app to test and the iOS test device and the laptop are connected to same WiFi network. I'm able to set up the proxy and instal burp certificate in the device and capture requests, but once I connect to...

Last updated: Feb 12, 2021 10:23AM UTC | 1 Agent replies | 0 Community replies | How do I?

i am just lerning bruteforce attcks from your lab

I have places the usernames in the payload set but while selecting payload set 2 i m not able to find it in a dropdown list can you please me regarding this

Last updated: Feb 12, 2021 08:08AM UTC | 1 Agent replies | 0 Community replies | How do I?

Getting Error while running Private Collaborator Server

Any reason why Im not able to poll to the private collaborator server root# java -jar burpsuite_pro.jar --collaborator-server --collaborator-config=myconfig.config 2021-02-10 22:10:31.305 : Using configuration file...

Last updated: Feb 11, 2021 06:38PM UTC | 2 Agent replies | 2 Community replies | How do I?

Not able to update my Burp Professional suite from 2020.9.2 to 2021.2 version

Dear Sir/Maam, I am currently using Burp Professional suite licensed version 2020.9.2. I have downloaded the latest version i.e 2021.2 but not able to upgrade my Burp Pro. I tried installing the latest version using an...

Last updated: Feb 11, 2021 02:07PM UTC | 1 Agent replies | 0 Community replies | How do I?

API query

Hi, I have lots of powershell scripts calling the api (Graphql) and don't seem to see a way of linking a site to the folder its in on the UI. Both show up on the site tree below. But theres no link between...

Last updated: Feb 11, 2021 09:03AM UTC | 1 Agent replies | 0 Community replies | How do I?

Refusing to start browser

I have this error: "Refusing to start browser as your current configuration does not support running without sandbox" And when I run the Embedded Browser Health Check the only warning appears in "Checking headless...

Last updated: Feb 10, 2021 05:08PM UTC | 1 Agent replies | 0 Community replies | How do I?

HDI Make the Inspector sidebar bigger?

The Inspector sidebar is great but how do I expand it horizontally to see more of the parameter names/values?

Last updated: Feb 10, 2021 01:08PM UTC | 2 Agent replies | 0 Community replies | How do I?

Could not connect to any seed URLs.

Team, I tried to scan API using the IP and port number but after 5 mintues it is saying "Could not connect to any seed URLs. " I am using BurpSuite Enterprise Edition Kindly help me to proceed further. I have...

Last updated: Feb 10, 2021 11:18AM UTC | 1 Agent replies | 1 Community replies | How do I?

How do I make embedded chromium browser only request traffic I tell it to?

Whenever I fire up the embedded browser in Kali Linux, chromium contaminates the HTTP history with useless traffic trying to phone home to Google for various updates/checks/account/sync whatever. And I don't mean javascript...

Last updated: Feb 10, 2021 11:12AM UTC | 2 Agent replies | 3 Community replies | How do I?

Proxy service not starting while port is free

Hi, I have been testing a thick client application, but while i am trying to start the proxy listener on port 80, It says "Failed to start proxy service on 127.0.0.1:80. Check whether another service is already using this...

Last updated: Feb 10, 2021 10:54AM UTC | 1 Agent replies | 1 Community replies | How do I?

Unable to activate license

Hi Portswigger team, I have formated my mac and I am unable to reactivate the license on the same machine please help me asap

Last updated: Feb 10, 2021 09:03AM UTC | 1 Agent replies | 0 Community replies | How do I?

macOSX V11.2 Big Sur, OWASP BWA and Virtual box--Home Hacking CyberSec Lab

The scenario.....finished Web Academy Labs. During the labs discovered that macOSX has some incompatibility issues with Burp Suite and the Web Academy Labs....No Problemo!!! Set up, on macOSX 11.2 (Big Sur) a virtual machine...

Last updated: Feb 09, 2021 09:01PM UTC | 0 Agent replies | 0 Community replies | How do I?

Cross Site Scripting

Hi, we are using the Burp professional version. We are doing cross site scripting testing on our application. There is one page where we can create an object with java script in the input values (ex: <script> alert(1)...

Last updated: Feb 09, 2021 03:32PM UTC | 1 Agent replies | 0 Community replies | How do I?

"Cross-site request forgery" scan doesn't detect anything in the "Lab: CSRF vulnerability with no defenses"

Hi, I'm working on the Lab: CSRF vulnerability with no defenses (https://portswigger.net/web-security/csrf/lab-no-defenses). I have been able to solve the lab so no issue there but the "Cross-site request forgery" scan...

Last updated: Feb 09, 2021 09:08AM UTC | 2 Agent replies | 1 Community replies | How do I?

Allowing the symbol "&" to be part of a string, instead of being something else

Hello, I've been trying to add the symbol "&" as part of a string in my POST request yet, I can't find out how. I tried backslash, "`", etc. I would truly appreciate it if you could help me out as soon as possible. Thank...

Last updated: Feb 08, 2021 06:26PM UTC | 2 Agent replies | 9 Community replies | How do I?

Page 194 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image