Burp Suite User Forum

Create new post

Repeater Connection reset

Hi Trying to test payload coming into one of our server (GET /producer/research_display.php?ID=-null+UNiON+ALL+SELECT+null,null,null,0x4f70656e5641532d53514c2d496e6a656374696f6e2d54657374,n HTTP/1.1) and receiving...

Last updated: Jun 13, 2018 09:08AM UTC | 1 Agent replies | 0 Community replies | How do I?

Stored XSS - detection tweaks

Hi, Usually, when I'm going through some wizard, e.g. "Create new XXX", all that is required is to create new item XXX is to do a simple POST with all data included. I can then send this POST into the Burp and run active...

Last updated: Jun 08, 2018 09:00PM UTC | 2 Agent replies | 1 Community replies | How do I?

Burp Collaborator disappeared from default dropdown menu?

Hello, I am suddenly unable to find Burp Collaborator on dropdown menu. I am already familiar with using Burp Collab, but ever since my license recently expired and I updated Burp, I am unable to find a way to launch the...

Last updated: Jun 08, 2018 07:52AM UTC | 1 Agent replies | 0 Community replies | How do I?

Getting Scan result report

I have added scans to the burp suite professional and notice that under my scanner and scan queue tab that issues have been identified, however I am unable to view or print out a report on what the vulnerability were....

Last updated: Jun 07, 2018 06:49AM UTC | 2 Agent replies | 3 Community replies | How do I?

Scope Control

Domains can be in one of three states: in scope, out of scope, or undecided. A domain is undecided if it is not mentioned by any of the in/out of scope rules. In the site map, I would like Burp Suite to hide domains that I...

Last updated: Jun 03, 2018 02:24AM UTC | 2 Agent replies | 2 Community replies | How do I?

VPN Connection - No Proxy Results

I'm having trouble with getting results from a website I am connecting to over a VPN. I can get results in the Burp Proxy without the VPN going to Google or some other public site. When the VPN is on in get no results...

Last updated: Jun 01, 2018 03:39PM UTC | 1 Agent replies | 1 Community replies | How do I?

replace license file

Hello, My company has purchased a 6-user license file to be used by its empoloyees. What can we do in the event of an employee quitting or being fired, so that that employee will not be able to use that license? Is...

Last updated: May 31, 2018 02:18PM UTC | 1 Agent replies | 0 Community replies | How do I?

Java Error Occured during Pentesting on .jsp webpage

I have been prompted with the below java error on doing the Security testing with help of burp suite scanner to test for vulnerabilities . I would like to inform that response code of response is 400, 404 etc and session is...

Last updated: May 31, 2018 08:02AM UTC | 2 Agent replies | 1 Community replies | How do I?

cannot get burp proxy to work with firefox

not sure what is going wrong with this. I have all settings correct. In burp i have the interface set to 127.0.0.1 and port set as 8080 (I have tried other ports as well). In firefox I Have the proxy set to...

Last updated: May 29, 2018 07:19AM UTC | 2 Agent replies | 2 Community replies | How do I?

How do I manual add a vulnerability

Using the intruder functionality, i saw the application was vulnerable to a XSS (with a custom payload). Active/Passive Scan doesn't find it. So I have a hit but how can i flag this payload/result with this params as a...

Last updated: May 23, 2018 03:02PM UTC | 7 Agent replies | 7 Community replies | How do I?

Unable to intercept and edit requests and responses in Android Application.

Hello, Am testing an e-commerce application on my Xiaomi android mobile running on 4.4.4. I'm able to see the requests and responses but before I edit and change them, they reach their destination. i.e when i try to edit...

Last updated: May 23, 2018 11:42AM UTC | 7 Agent replies | 10 Community replies | How do I?

Burp Spider deleted controls in a SalesForce application

Hi - We recently spidered a Salesforce application and this resulted to changes in the application such as: Deleted custom field Changed the UI Skin Changed Enable Drag-and-Drop Editing on Calendar Views from on...

Last updated: May 18, 2018 07:23AM UTC | 1 Agent replies | 0 Community replies | How do I?

Purchased Burp Suite but have not received License

I purchased Burp Suite on May 10 for $349. It has been 5 days and I have still not received my License. Burp Suite is terrible and no one every responds to emails.

Last updated: May 15, 2018 07:03PM UTC | 0 Agent replies | 0 Community replies | How do I?

Import Client SSL Certificates (.CER files)

I was trying to load a .CER file into the Client SSL section for the proxy server, however it says it requires a password. Is there any way around this? I tried the Openssl method of setting a custom password except there...

Last updated: May 15, 2018 01:36PM UTC | 2 Agent replies | 1 Community replies | How do I?

Automate Burp License Activation

We are working on a project, where we wanted to deploy Burp on a container in a ci/cd. Is there a way to automate the Burp License Activation process programmatically eitherway in a headless mode ? Has anyone given it...

Last updated: May 15, 2018 08:27AM UTC | 1 Agent replies | 0 Community replies | How do I?

certificate_unknown

I have an iOS app I'm testing on an iPhone 5c running iOS 10.3.3. The Burp certificate is correctly installed on the device as I'm able to see https web requests and https app requests from other applications within Burp...

Last updated: May 11, 2018 03:55PM UTC | 1 Agent replies | 0 Community replies | How do I?

How do i prevent cookie ID injections in the request parameter?

I have a case where we recorded a bunch of URL's and re-scanning them. During the re-scan the session expired. So to create an active session i have created a session handling rule to trigger login and create a new Session...

Last updated: May 11, 2018 01:04PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp/run analytics

I would like to know how to run analytics

Last updated: May 11, 2018 09:02AM UTC | 1 Agent replies | 0 Community replies | How do I?

Fuzz APIs ?

Do burp is having any extension which can help in Pen test of APIs ? Like another tool API fuzzer ? along with Intruder what else can be used to do API pen test automatically ?

Last updated: May 10, 2018 12:43PM UTC | 1 Agent replies | 0 Community replies | How do I?

How to stop DOM Based Link Manipilation in struts2.5

Hi, Could you please help me resoving issue of DOM Based Link Manipilation in struts2.5. Its saying whitelisting of URLs, which I have already done in web.xml, but still its not stopping URLs which are already...

Last updated: May 10, 2018 09:52AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 285 of 322

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image