Burp Suite User Forum

Create new post

Burp update HTTP header

Hi, I'm wondering if there is a simple way to update the HTTP header. Basically when a specific request is made a new token is sent in the response. How can I take that value from the response and put it into the header...

Last updated: Aug 09, 2018 11:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

Static and Dynamic scan of .NET MVC web application coding in development environment

Hi, I am planning to buy two licenses of Burp Professional. Does Burp professional license includes all the modules/functionalities including static/dynamic scanning of developers actual coding. If not what should I need to...

Last updated: Aug 09, 2018 10:53AM UTC | 1 Agent replies | 0 Community replies | How do I?

PLS HELP

How do i use it pls send a video for understanding pls tell..... i have a latest laptop...SO PLS HELP....BY GIVING TRAINING

Last updated: Aug 06, 2018 07:12AM UTC | 1 Agent replies | 0 Community replies | How do I?

Spider request queue not stopping.

Hi, I have stopped the spider from running and cleared the queues. This was roughly 30 minutes ago. However, more and more requests are still getting queued. Why is this happening and how do I stop it?

Last updated: Aug 05, 2018 05:23PM UTC | 4 Agent replies | 4 Community replies | How do I?

Reroute Domain on Game Client

Hello, i’m working on a game called Marvel Contest of Champions, and i can intercept its proxy with Burp Suite and it gives me the different cloud servers that the data is stored on(mcoc-1800-fbaem.sparxcdn.net) and many...

Last updated: Aug 03, 2018 04:18PM UTC | 1 Agent replies | 1 Community replies | How do I?

Scanner: Ignore errors and continue

I am testing a target which intentionally resets the TCP connection if it receives certain kinds of invalid inputs. When performing an active scan, Burp will only perform so many requests before it aborts and reports...

Last updated: Aug 03, 2018 11:45AM UTC | 2 Agent replies | 2 Community replies | How do I?

How do I download a list of payloads

Where can I get a list of payloads?

Last updated: Aug 03, 2018 07:16AM UTC | 2 Agent replies | 1 Community replies | How do I?

export spider traffic

After spider the host, how can I export the traffic of spider to other tools ?

Last updated: Aug 01, 2018 07:09AM UTC | 3 Agent replies | 2 Community replies | How do I?

Authentication Failure from xyx.com

Hi All, Need urgent help, We have a financial Application(xyz) and we are running burp suite for that. And After capturing the target site. i.e.. Login to application >> Navigating entire application links and navigation...

Last updated: Jul 31, 2018 12:55PM UTC | 1 Agent replies | 0 Community replies | How do I?

Scanning abandoned due to too many errors

Hi, I am trying to scan and almost all the requests are getting abandoned due to errors and when checked in Alerts tabs it says "Timeout in transmission from xyz.com" What is missing here?

Last updated: Jul 31, 2018 07:45AM UTC | 3 Agent replies | 2 Community replies | How do I?

Repeat spidering with corrected authentication

I spidered a site, and many of the pages returned 401s. I've since fixed the project authentication settings, and I want to re-spider the pages that returned 401s. If I select the target and send it to spider, nothing...

Last updated: Jul 30, 2018 12:30PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp's CA certificate was blocked from server

I'm having a problem creating an api for my application https://imgur.com/a/gFxGTZQ - In the above image I used the same request for burp suite and post man. Post man working and burp suite is not - when i use burp...

Last updated: Jul 27, 2018 01:10PM UTC | 3 Agent replies | 3 Community replies | How do I?

Testing web services

Is burp capable of testing web services - can all test cases defined in OWASP cheat sheet be tested ? https://www.owasp.org/index.php/Web_Service_Security_Testing_Cheat_Sheet

Last updated: Jul 27, 2018 11:22AM UTC | 2 Agent replies | 1 Community replies | How do I?

How to only scan once for one url or one host

in some situation, the scanner only need send one request per one URL or one host to detect the vulnerability. but doActiveScan function in IScannerCheck called per insertPoint. that's say:doActiveScan called multiple...

Last updated: Jul 27, 2018 09:13AM UTC | 2 Agent replies | 1 Community replies | How do I?

How do I get burp pro to listen on eth0?

I have installed burp on Azure / Ubuntu server and am trying to get it to listen on eth0 so I can access it remotely from my laptop or my workstation. Maybe my expectations are wrong, but it seems this should be an easy...

Last updated: Jul 27, 2018 09:10AM UTC | 1 Agent replies | 0 Community replies | How do I?

Unable to intercept with Android mobile app using Burpsuite

1.i am using genymotion virtual android device. 2.I have download Google Nexus 5X-7.1.0 3.I have set the necessary proxy setting for burp suite ,as well as wifi proxy connection in genymotion. 4.I have download and...

Last updated: Jul 25, 2018 07:27AM UTC | 2 Agent replies | 1 Community replies | How do I?

Need steps to Record the Jmeter REST API Request

Hi Team - I want to perform security test on REST API services and i'm planning to use burp suite so that it listens to jmeter and capture the web service request which jmeter is sending to server . Also let me know what...

Last updated: Jul 23, 2018 10:48AM UTC | 2 Agent replies | 1 Community replies | How do I?

session id

hi I am creating a web application which will b used by many customers of my company.In this application I want to track my session id and protect it from 3rd party users (who act as man in middle and attack session id and...

Last updated: Jul 23, 2018 08:47AM UTC | 1 Agent replies | 0 Community replies | How do I?

Headless scan in BURP with bearer token

I am trying to do some automated scanning with BURP in an ervironment that requires token authentication. For this purpose I need to login before each session to get a bearer token. This token is in the body of the login...

Last updated: Jul 20, 2018 11:52AM UTC | 3 Agent replies | 5 Community replies | How do I?

No internet connection error when attempting to connect to Google Play Store.

Have cacert.cer installed on Android device and surfing web http and https sites. However when attempting to go to Google Play Store a message there is "No internet connection. Make sure WiFi or cellular data is turned on,...

Last updated: Jul 20, 2018 07:39AM UTC | 1 Agent replies | 1 Community replies | How do I?

Page 270 of 309

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image