Burp Suite User Forum

Create new post

Intercepting data on Android Device

Hello, Please can someone help me with the following: I am trying to use Burp Suite to see my network traffic on my mobile device however when I connect it I can see the request in the Burp Suite however my phone...

Last updated: Jul 05, 2018 06:58AM UTC | 2 Agent replies | 2 Community replies | How do I?

Clarification on Webservices scanning

I have some clarifications on web service testing. Question 1: Is burp suite capable of performing testing webservices against all known vulnerabilities associated with web services ? All scanning options present under...

Last updated: Jul 04, 2018 09:03AM UTC | 4 Agent replies | 3 Community replies | How do I?

How do I configure BURP to ignore method OPTIONS on scope?

Hello there, How do I configure BURP to ignore method OPTIONS on scope? This is very annoying. Tks!

Last updated: Jul 04, 2018 08:47AM UTC | 3 Agent replies | 2 Community replies | How do I?

Connection types

Hello. In every single site my connection is closed is it ok?Can i use burp with closed connection or there is something wrong

Last updated: Jul 04, 2018 07:12AM UTC | 2 Agent replies | 2 Community replies | How do I?

how to generate different token or session id for every request that i made using intruder?

how to generate different token or session id for every request that i made using intruder? your support already give a suggest, i can change the token using random value using payload. But from my understanding, the...

Last updated: Jul 02, 2018 01:43PM UTC | 1 Agent replies | 0 Community replies | How do I?

Letsencrypt Support

Hi all, Is there a recommended way to use Letsencrypt certificates on collaborator at all? We're using it to handle all of the DNS for a dedicated domain solely for Burp so setting up another DNS server for one request to...

Last updated: Jul 02, 2018 07:22AM UTC | 2 Agent replies | 2 Community replies | How do I?

Burp Pro v1.7.34

Can i get trial version for win64? 2 day of trial period will be fine to check all i need. Thanks

Last updated: Jun 28, 2018 08:15AM UTC | 1 Agent replies | 0 Community replies | How do I?

Android traffic interception when app is accessed via VPN

hi , My Android app is accessible only when connected via VPN connection on my Android device. Please tell me how to intercept app traffic on my laptop running Burp tool Regards, Garry

Last updated: Jun 27, 2018 07:12AM UTC | 3 Agent replies | 2 Community replies | How do I?

Get the type of check being performed by the scanner using a BurpExtender script

Hi, When implementing a BurpExtender script, and specifically a http listener, I know i can check if the Scanner generated the http message like so: def processHttpMessage(self, toolFlag, messageIsRequest,...

Last updated: Jun 26, 2018 01:38PM UTC | 1 Agent replies | 1 Community replies | How do I?

Licensing and number of activations

Hi guys, while requesting for Burp trial license , i gave the 'number of users' to be one. Does that mean burp can be installed only once ? Because i was able to install in 3 locations (different systems) and the 4th time...

Last updated: Jun 26, 2018 10:22AM UTC | 0 Agent replies | 0 Community replies | How do I?

Doesn't Intercept Messages

When I run WebGoat as described in its user guide, it works exactly as it should. And, whenever I run Burp Suite as described in its documentation, it also works perfectly. However, when I attempt to use Burp Suite as a...

Last updated: Jun 25, 2018 07:13AM UTC | 1 Agent replies | 0 Community replies | How do I?

The type element in the XML report

From manual about Reporting: >> The type element contains an integer that uniquely identifies the issue type (SQL injection, XSS, etc.) For example, for SQL injection Type index is 0x00100200 (from here: ...

Last updated: Jun 22, 2018 10:15AM UTC | 1 Agent replies | 0 Community replies | How do I?

"failed to save project burp.czi"

Hey. When you save the project, here comes this error, tell me how to fix it error screenshot http://prntscr.com/j7d1wd

Last updated: Jun 22, 2018 08:07AM UTC | 1 Agent replies | 2 Community replies | How do I?

download sarfari CA certificate

According to the instructions, it says: In Safari, visit https://portswigger.net.In the warning dialog titled "Safari can't verify the identity ..." click "Show Certificate". Well, i go to to that site, using Safari, and...

Last updated: Jun 21, 2018 12:29PM UTC | 1 Agent replies | 0 Community replies | How do I?

Scanning abandoned due to too many errors (0% complete)

Hi, I am trying to scan and almost all the requests are getting abandoned due to errors and when checked in Alerts tabs it says "Timeout in transmission from xyz.com". Initially my application was accessible,and after...

Last updated: Jun 21, 2018 12:18PM UTC | 1 Agent replies | 0 Community replies | How do I?

Disable autocomplete inside Burp

Is it possible to disable Burp's autocomplete when entering in fields such as search term box in HTTP history? I have issues where it doesn't go away and leaves a blank box or I have to enter what I want and delete it...

Last updated: Jun 20, 2018 03:33PM UTC | 3 Agent replies | 3 Community replies | How do I?


Hi, I'm a relative n00b trying to understand DOM-based XSS from the following issue reported by Burp. I'm trying to figure out if this is false-positive or not. Having difficulty putting together a POC, identifying the...

Last updated: Jun 19, 2018 04:17PM UTC | 1 Agent replies | 0 Community replies | How do I?

Needs to know the kind of Security Pen-test in Prod Environment -Web AppSec

Can someone tell me about the various security testing in Web Application involved without creating any junk data in DB or collapsing Duplicating data with original data present and testing will be done in Production...

Last updated: Jun 19, 2018 01:58PM UTC | 2 Agent replies | 1 Community replies | How do I?

about web sockets

we are using web socket to connect multiple systems, so one of my pc is having to capture the login request for an application so in that time when i capturing the request automatically it is capturing another url of...

Last updated: Jun 18, 2018 11:05AM UTC | 1 Agent replies | 0 Community replies | How do I?

How do I run and existing project with saved target on command line

I captured traffic from the Buite Suite. Then I go from Target > Site Map > I righted click and did a active scan on the host I captured. I export the result manually and saved my project to my_captured_project.burp My...

Last updated: Jun 18, 2018 06:54AM UTC | 4 Agent replies | 3 Community replies | How do I?

Page 288 of 326

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image