Burp Suite User Forum

Create new post

Use Firefox browser as a proxy.

This may not be correct platform to ask the question. I had given a presentation on Burp suite, One question came to me that "Why Firefox is preferred browser to set proxy with ? " What to answer this question ? I am...

Last updated: Apr 18, 2018 01:41PM UTC | 1 Agent replies | 1 Community replies | How do I?

Compare site maps with different Cookies

I have an application with Basic Authentication as login. If access is granted, the user is tracked by cookie (PHPSESSID). The application was spidered and scanned as admin user. Now I want to compare the site map with...

Last updated: Apr 17, 2018 02:05PM UTC | 2 Agent replies | 1 Community replies | How do I?

How to know if spider has been done completely.

There are only 2 states of spider "Spider is running" or "Spider is paused". How I would be knowing that crawling has been completed ? Since it is not toggling automatically.

Last updated: Apr 17, 2018 09:10AM UTC | 1 Agent replies | 0 Community replies | How do I?

How can I uninstall Burp's extension ? I dont need a few now

Recently we had a pen test cycle to run, I had install a few extenders through Bapp store, Now I don't need them. From where I can uninstall them ? I don't want them to be shown in grid anymore.

Last updated: Apr 16, 2018 01:06PM UTC | 1 Agent replies | 0 Community replies | How do I?

Potential False Positive DOM Based XSS - 2

Hi, Burp reported this below lines as Dom Based XSS vulnerability with Severity: High, Confidence: Firm. I didn't find a way to exploit this lines within a scenario since document.body.classList.add function is used only...

Last updated: Apr 16, 2018 08:10AM UTC | 1 Agent replies | 0 Community replies | How do I?


hi team can u tell me how i set up and run the burp suite. i already download burp suite community edition .

Last updated: Apr 05, 2018 07:10AM UTC | 1 Agent replies | 0 Community replies | How do I?

Potential False Positive DOM Based XSS

Hi, Burp reported just this below line as Dom Based XSS vulnerability as Severity: High, Confidence: Tentative. I didn't find a way to exploit this line within a scenario since there is no parameter exists that can be...

Last updated: Apr 04, 2018 09:27AM UTC | 1 Agent replies | 0 Community replies | How do I?

Bypass racaptcha on website login

How do i bypass recaptcha on website login/signup page at the time of making intruder attack?

Last updated: Apr 03, 2018 04:25PM UTC | 2 Agent replies | 2 Community replies | How do I?

Can you implement the Send Intruder technique to a project in Java, Android Studio or php??

I would like to know how Burp Suite performs the capture of the http request and how it is modified and how it is sent back to the destination server with the POST method. And I would also like to know if that attack can...

Last updated: Apr 03, 2018 10:16AM UTC | 1 Agent replies | 0 Community replies | How do I?


Hi. I am trying to use burp suite for testing on a site but the site has a captcha and not sure how I can make burp suite bypass it ? The captcha is a image with 4 digits. I assume every time the page is loaded it changes...

Last updated: Apr 03, 2018 10:11AM UTC | 1 Agent replies | 1 Community replies | How do I?

Burp workings

Hii...I have tomcat server running which has vulnerable websites for the purpose of learning how to hack them..I have installed burp suite and now it is intercepting the requests but not forwarding the requests to tomcat...

Last updated: Apr 03, 2018 07:34AM UTC | 1 Agent replies | 0 Community replies | How do I?

Delete issues through extension

I created a burp extension in python that scans from a list of URLs and generates a report after it is done. I'm not able to find a method in the API that allows me to clear all reported issues. Is this possible? If so it...

Last updated: Apr 03, 2018 07:29AM UTC | 1 Agent replies | 0 Community replies | How do I?

WCF binary decode failure

I'm testing a fat client application that passes all its traffic through SSL, WCF binary encoded. It also looks like it is being compressed (Content-Type: x-deflate) which adds another level of PiTA. I'm using the "WCF...

Last updated: Mar 26, 2018 08:10AM UTC | 2 Agent replies | 2 Community replies | How do I?

How do I calculate the length in the proxy http history

I was wondering about the size in the length column (in proxy http history),it has been said in the documentation that the length refer to the response length but it dose not seems like this, for example I have length is...

Last updated: Mar 26, 2018 08:06AM UTC | 1 Agent replies | 0 Community replies | How do I?

Scanner very slow

Hi - I'm attempting a non-authenticated point and click scan of our SaaS application. There are over 1,300 items, many of which are 404.aspx and the help system. Why is it so slow? When I started it 12 hours ago, it seemed...

Last updated: Mar 26, 2018 07:56AM UTC | 1 Agent replies | 0 Community replies | How do I?

Basic Intruder Question using Base64 Encode

Im trying to use Burp to access my base64 protected site to see if it is possible, however I am having a problem learning about where positions should be tagged at in a base64 string. User-Agent: Mozilla/5.0 (Windows NT...

Last updated: Mar 25, 2018 07:37PM UTC | 1 Agent replies | 1 Community replies | How do I?

Enable parameters to be identified in a Target Analysis

I am running an instance of BURP Pro (v1.7.32) with both Passive and Active scanning enabled. When I run a Target Analysis and review what parameters were identified no of the password parameters were identified. Which...

Last updated: Mar 23, 2018 02:59PM UTC | 3 Agent replies | 2 Community replies | How do I?

XSS in text/javascript Content-Type

Burp scanner reports that on the text/javascript content type, XSS is possible with Severity: High, Confidence: Certain but I didn't find a way to prove it with a PoC. All modern browsers behave text/javascript files not as...

Last updated: Mar 23, 2018 01:40PM UTC | 1 Agent replies | 0 Community replies | How do I?

Change part of a URL in a project

Hi, We have extensively done browsing to record as most URLs as possible for a particular website, and tested that version, which resides in: www.mydomain.com/uat/application. Now we've moved the same website to...

Last updated: Mar 23, 2018 10:01AM UTC | 2 Agent replies | 1 Community replies | How do I?

Http headers manipulation

Burp tool is manipulating my http origin and referrer header. Please provide a way around to disable that

Last updated: Mar 23, 2018 08:39AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 287 of 322

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image