The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CSRF PoC vulnerability only succeeds while Proxying through Burp

This may be a dumb question as I may not fully understand how this CSRF vulnerability is working. Scenario: Within the application using Spring / Spring Webflow, and Spring Security. I am able to create a PoC with Burp...

Last updated: Sep 10, 2020 07:44AM UTC | 1 Agent replies | 2 Community replies | How do I?

Examples of business logic vulnerabilities

Hello! When I try to complete lab https://portswigger.net/web-security/authentication/multi-factor/lab-2fa-broken-logic at step to brute force 2fa code I recive 400 code after some tries and message like this:" HTTP/1.1...

Last updated: Sep 10, 2020 01:07AM UTC | 2 Agent replies | 3 Community replies | How do I?

Communication error while scanning

Hi, When i run passive scan or active on my respective website, it throws communication error. This error is showing in event log. Please help me in this issue.

Last updated: Sep 09, 2020 11:19AM UTC | 3 Agent replies | 6 Community replies | How do I?

Stuck in Business Logic Flaw Lab: Low-level logic flaw

Not sure how to solve this. Any suggestions?

Last updated: Sep 09, 2020 08:08AM UTC | 1 Agent replies | 0 Community replies | How do I?

Stuck in Lab: Low-level logic flaw

i need help in the mentioned lab, at least in which area we have to use Burp Intruder or Turbo Intruder more hints please :)

Last updated: Sep 08, 2020 07:15PM UTC | 1 Agent replies | 1 Community replies | How do I?

How do I login?

I entered my email address and the retrieve password. but i cannot login.

Last updated: Sep 08, 2020 12:44PM UTC | 1 Agent replies | 0 Community replies | How do I?

activation limit reached

Hi, It seems that I have used most of my activations while playing with different OS versions in my VMS. Could you please add one or two more activations please? Kind Regards

Last updated: Sep 08, 2020 11:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

scan ID from POST response

I'm initiating a scan using Burp POST REST API (curl -vgw "\n" -X POST 'http:burpURL' -d '{"urls":[targetURL]}'), I see even number (scan / task_id) as a part of HTTP response location header but if I initiate a scan using...

Last updated: Sep 08, 2020 10:09AM UTC | 2 Agent replies | 1 Community replies | How do I?

Burp to command

Hi there, Is there a way to run the sitemap demo.testfire.net with external command and save to a file. Example, I want to run sslscan <sitename> gobuster -u http://<sitename>/ -w...

Last updated: Sep 08, 2020 08:29AM UTC | 2 Agent replies | 1 Community replies | How do I?

Integrating BurpSuite Enterprise Edition with Defect Dojo

How can I import BurpSuite Enterprise Edition scan reports into Defect Dojo? What format should I use to export the reports? I downloaded the HTML report and then imported into Defect Dojo, but the result is empty: the...

Last updated: Sep 08, 2020 08:19AM UTC | 1 Agent replies | 0 Community replies | How do I?

unable to provide license key

i am unable to upload license key, i was a trial user b/w feb and march this year, i got it extended till 8 October, starting form today, but i am unable to upload this key while using burp enterprise edition.

Last updated: Sep 08, 2020 07:54AM UTC | 1 Agent replies | 0 Community replies | How do I?

license

hello i still not get my link and license. thank you

Last updated: Sep 08, 2020 07:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp Suite Bruteforce with a Combo List ?

Hello .. I want to Bruteforce Login Page but i want to use a Combo List is it Possible ? Example Usernames:1 2 3 4 Passwords:5 6 7 8 I...

Last updated: Sep 07, 2020 01:09PM UTC | 1 Agent replies | 0 Community replies | How do I?

Intruder password probing

What technique i use if i want to run intruder where i know password length and want to run it one char by char in single attack where it starts checking for next char as soon as current char is found successfully so that i...

Last updated: Sep 07, 2020 11:34AM UTC | 1 Agent replies | 0 Community replies | How do I?

generate connection to websocket

Hi, How could I generate a new websocket connection. I can capture websockets from website and send them to repeater. But I would like to establish the connection flow from zero, and I need to create a websocket...

Last updated: Sep 07, 2020 08:19AM UTC | 1 Agent replies | 0 Community replies | How do I?

Clarification on the burp license purchased

Dear Team, I have couple of questions, 1. We don't have any license which will expires on 05th September. However we have a license Key which will expires on 06th Sep 2021. We have not purchased any license. 2. If...

Last updated: Sep 07, 2020 08:11AM UTC | 3 Agent replies | 3 Community replies | How do I?

Burp Suite Pro

Hi there, Is there any form of integration for Burpsuite Pro to Netsparker, Metasploit Pro, Nmap, Qualysguard or Burp Suite in any form?

Last updated: Sep 07, 2020 08:04AM UTC | 2 Agent replies | 1 Community replies | How do I?

I can't complete a sql lab

Is there a problem at this lab? Because i am not able to execute correct payloads. https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft

Last updated: Sep 07, 2020 07:42AM UTC | 1 Agent replies | 1 Community replies | How do I?

Cant Activate my burp

Hello, Please can reset my license, I reinstall my windows with a vm with Kali, Need activate both burp profesional. Past activation are not requiered anymore. Thanks

Last updated: Sep 07, 2020 07:04AM UTC | 1 Agent replies | 0 Community replies | How do I?

Redirection issue when using Intruder

The request which i pass to intruder is POST request. When i start the attack, i see that the response code is 301 and since i have configured intruder to follow redirects, it follows the redirection. But the issue is, when...

Last updated: Sep 06, 2020 12:55PM UTC | 1 Agent replies | 1 Community replies | How do I?

Page 218 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image