Burp Suite User Forum
For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.
in authentication lab Username enumeration via account lock i have been brute forcing all the username with adding count parameter in the body and doing as shown in the solution but i only receive response which shows...
Hey there , I exploited it as much as I could and took help from writeups also but the password I obtained is of carlos how do i get the admin also the solution is not clear to me others say that carlos pwd act as their...
Hi, I am doing Lab: Blind SQL injection with conditional responses For this, after setting payload and other options, Intruder must show a tick mark at any position. But it is not showing. As per the lab, it is...
I am using Kali with pre-installed Burp Suite Community edition. I cannot find a way to upgrade to the pro license. I am guessing this is impossible. Do I need to fully uninstall in order to see the "license" entry in...
It has been over 24 hours that I have made the purchase. The amount has been debited from my account and I am yet to receive the license key. In addition to this, I have sent a mail to office@portswigger.net and have had no...
We have pages with hidden get parameter and burp is not able to see and scan them - can I add them manually so burp can scan them? If so, how can this be done?
Picked up _JAVA_OPTIONS: -Dawt.useSystemAAFontSettings=on -Dswing.aatext=true WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by burp.oh...
Hello there, mailed to you too. Due to private causes, I want to refund the Burp Suite that I bought days ago. Not used more than 1-2 days. Thank you.
I have provided a url to burp to scan. Burp is blindly running get requests on that though it is intelligent enough to know which all http methods are allowed for that request.
Hi, I need write custom extension to keep pairs from login request: login / auth-code from cookies. I think, that I can catch all login requests and after that write login credentials to the file. After that, I want to...
I am trying to register for burp suite trial but every time a popup shows and says "Company name required" even though I am filling company name. Please help in this.
Hi, I am currently testing an API which has the following POST request in JSON format: { "Code1": "123", "Time": "2020-07-20 10:00:00", "Amount": 1, "List": [{ "Code2": "abc123", "Color":...
Hello, I maybe doing things the wrong way but I am trying to get all issues type of all scans with the API and the request below leads me to error 77 "Unexpected Graph Error". Any help available ? query getIssues { ...
I am using below command to start Burpsuite Start-Process "`"C:\Program Files\Java\jre1.8.0_201\bin\javaw.exe`"" -ArgumentList "-jar","-Xmx1G","`"C:\Program Files\BurpSuiteCommunity\burp-rest-api-2.1.0.jar`"","`"C:\Program...
HI, BurpSite Enterprise what are the below can be tested .. 1. Web side vulnerabilities 2. Android app scanning to find vulnerabilities 3. Server side testing vulnerabilities scanning. 4. Static code...
Stuck with wizard
i am unable to access the solutions tab in the labs
When the severity of a found vulnerability is classified as "information", what does it really mean? And also what is the degree of severity. Based on the other severity category it is obious a high is more severe than a...
Hi there, I already have the license key of Burp shared by my company. Can you share me the downloadable .exe of burp suite community edition? Where I can put the license key start working on the Burpsuite....
Unable to view solutions in Web Security Academy, Drop down button is not working.
Page 225 of 332
Your source for help and advice on all things Burp-related.