The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

how do i convert multipart gzip to original file

during my research i'm intercepting some packages like this: Content-Type: multipart/form-data; boundary=cLXA2xHy63hD9QS92t_yJwlwnL8vVb Accept-Encoding: gzip, deflate X-FB-HTTP-Engine: Liger Connection:...

Last updated: Nov 16, 2019 07:56PM UTC | 2 Agent replies | 1 Community replies | How do I?

Crawling and Auditing a Shibboleth Protected website

We are trying to crawl and audit a shibboleth protected site and am only seeing the public facing pages being crawled and audited.We can see the sitemaps and items when manually traversing the site via the proxy and browser....

Last updated: Nov 15, 2019 10:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

http://burp/ not reachable

hi folks I am trying to install the CA for firefox and the suggestion to download from http://burp/ results in the site not being reachable. Is the site down? I have tried this from multiple computers and networks and...

Last updated: Nov 14, 2019 02:36PM UTC | 2 Agent replies | 1 Community replies | How do I?

IPV6 scanning through Burp 2.1.5 tool

Hi Team, I need to do IPV6 scanning using latest Burp 2.1.5 tool on windows. steps 1: https://[IPV6]/ entered in the browser. step2 . At Burp side Intercept is On on windows Machine. Step3: Burp cannot able to get...

Last updated: Nov 14, 2019 12:58PM UTC | 1 Agent replies | 0 Community replies | How do I?

Pass the Build in Jenkins even Burp_scan shows vulnerabilities for Burp Enterprise

Team, Could you please let me know how to pass the build in Jenkins despite vulnerabilities being identified using the burp enterprise edition? The BURP_SCAN_STATUS is succeeded in Jenkins but Build is marked as Failure...

Last updated: Nov 14, 2019 12:35PM UTC | 1 Agent replies | 1 Community replies | How do I?

How to run active scan from burp command line for burp 2.1

I am taking help of headless burp extension and running the below command java -jar -Xmx1g -Djava.awt.headless=true "C:\Program Files\BurpSuitePro\burpsuite_pro.jar" --project-file=project.burp -c config.xml but this will...

Last updated: Nov 14, 2019 11:39AM UTC | 1 Agent replies | 0 Community replies | How do I?

Not able to intercept specific HTTPS traffic

Hello, I am not able to intercept the HTTPS traffic using burp. I have installed certificate. I able to intercept the https://www.google.com but not able to intercept one specific URL. When i set the proxy, URL main page...

Last updated: Nov 14, 2019 10:46AM UTC | 4 Agent replies | 3 Community replies | How do I?

Can I passively scan some specific words?

Hi, I would like to scan some specific words such as "Storage" or "DB" in JS files. Can I do the same using passive scan function in Burp?

Last updated: Nov 13, 2019 12:05PM UTC | 3 Agent replies | 2 Community replies | How do I?

lab question

how am i supposed to steal cookies from this lab "Lab: Exploiting cross-site scripting to steal cookies" without having burp professional and without using Burp Collaborator client I've tried redirecting users to my site...

Last updated: Nov 12, 2019 01:05PM UTC | 5 Agent replies | 5 Community replies | How do I?

Exporting site map

Hi, I am developing an extension that will perform the same functionality as it can be done manually by right clicking on items in Target's site map or Proxy history and then selecting "Save items". Using manual process I...

Last updated: Nov 12, 2019 12:09PM UTC | 3 Agent replies | 2 Community replies | How do I?

Burp API

Hi, team! I want to automate BurpSuite scans using burp's REST API (https://portswigger.net/blog/burps-new-rest-api) but receive errors when sending requests to start the scan. I run burp in headless mode. My request...

Last updated: Nov 12, 2019 08:27AM UTC | 1 Agent replies | 1 Community replies | How do I?

Turn off crawling in enterprise?

Is there a configuration which will let me not crawl the site I'm crawling at all and JUST scan the URL(s) provided? I have an application which contains the ability to self-register a user, and I'd like to be able to...

Last updated: Nov 11, 2019 03:32PM UTC | 1 Agent replies | 0 Community replies | How do I?

JSON Response hidden data

Hey there burp community, Here is my question : I was using the repeater tool to send requests and in the response some of the data was hidden/censored by an asterix (*) (eg....

Last updated: Nov 11, 2019 09:20AM UTC | 1 Agent replies | 0 Community replies | How do I?

i can get in 'http://burp/' but other websites

i run proxy 127.0.0.1:8080 with burp suite and set chrome or firefox proxy at 127.0.0.1:8080, finally,i just can enter 'http://burp/' to download certificate . and all the other websites, i couldn't get in .why? why?

Last updated: Nov 11, 2019 08:55AM UTC | 1 Agent replies | 0 Community replies | How do I?

How do I run passive scan on a specific request

It does not appear to be possible to run _passive_ scan rules on one or multiple requests. There used to be an option in the right-click menu in proxy, target and other.

Last updated: Nov 11, 2019 08:38AM UTC | 1 Agent replies | 0 Community replies | How do I?

How to use burpsuite pro shipped with burp enterprise

Hi Team, I want to know how to use burpsuite pro shipped with burp enterprise version. Is it possible to use it or trigger it with vmware/burp-rest-api. Kindly let me know how this can be worked on?

Last updated: Nov 11, 2019 08:28AM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp Extender support in Free Edition

We currently pay for the Pro Edition however numerous cases have arisen to develop tools for continued use by other individuals who currently do not pay for the Professional Edition. Is there any support for Extensions in...

Last updated: Nov 11, 2019 02:11AM UTC | 3 Agent replies | 3 Community replies | How do I?

how burpsuit pro track this 'stranger' or assessment my PC to prove my PC have been hacked ?

hi, i have PC for penetration test for internal application. but i suspect my PC has been hacked by other stranger. how burpsuit pro track this 'stranger' or assessment my PC to prove my PC have been hacked ?

Last updated: Nov 08, 2019 10:45PM UTC | 2 Agent replies | 2 Community replies | How do I?

Web Security Academy - Blind XXE Lab 3 ("Exploiting blind XXE to exfiltrate data using a malicious")

Dear Support, I tried the challenge to receive the /etc/hostname using the following: Initial XML in HTTP request: <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE foo [ <!ENTITY % xxe SYSTEM...

Last updated: Nov 07, 2019 07:11PM UTC | 1 Agent replies | 2 Community replies | How do I?

OWASP top 10 reporting?

Is there a way to customize the reporting to show OWASP top 10 report or how can we get OWASP top 10 reporting? Thanks

Last updated: Nov 07, 2019 11:48AM UTC | 3 Agent replies | 2 Community replies | How do I?

Page 263 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image