Burp Suite User Forum

Create new post

Cross-site scripting (DOM-based)

Burp has created two different tentative DOM XSS issues with this description: "The application may be vulnerable to DOM-based cross-site scripting. Data is read from location and passed to $() via the following...

Last updated: Jan 30, 2018 07:42AM UTC | 2 Agent replies | 1 Community replies | How do I?

Locked due to many failed login attempts as soon as i scan my application

Issue 1: My application(https://test2.tstraining.com/) is getting locked due to many failed login attempts as soon as i scan my application. Am i sending bunch other invalid passwords ?? I see below article. I don't...

Last updated: Jan 25, 2018 10:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Viewing Issues

After running a scan using Community Version v1.7.30 in free mode, I do not see a the Issues tab under Target >> Site Map. After looking at posted screenshots, I see a set of tabs above the Request | Response tabs. I do not...

Last updated: Jan 23, 2018 04:19PM UTC | 1 Agent replies | 0 Community replies | How do I?


How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.

Last updated: Jan 22, 2018 04:12PM UTC | 1 Agent replies | 0 Community replies | How do I?


How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.

Last updated: Jan 22, 2018 03:31PM UTC | 0 Agent replies | 0 Community replies | How do I?

Remote host connection closed during handshake

Hi , Burp is not intercepting traffic when I am accessing app via company n/w with proxy However, when I am connected to my home n/w ( no proxy) I am able to intercept in Burp. Can you please advise...

Last updated: Jan 22, 2018 11:38AM UTC | 3 Agent replies | 3 Community replies | How do I?

Expression Language Injection Syntax

I'm trying to improve my understanding of expression language (EL) injections. The following injections were created by Burp...

Last updated: Jan 19, 2018 04:18PM UTC | 3 Agent replies | 1 Community replies | How do I?

Unable to use Burp with proxy

Setting my Firefox proxy server to for all protocols disallows me from connecting to any website at all. Error message: https://gyazo.com/dba7c96b3dd6920b33f1ccf2810b7826 Not only that, but the HTTP...

Last updated: Jan 19, 2018 08:44AM UTC | 2 Agent replies | 1 Community replies | How do I?

Restore installed extensions

Hey, Is it possible to install a selected number of extensions from BAppStore and restore them on Burp restart and new project creation? It is tedious to reinstall extensions everytime I start bounting on a new scope.

Last updated: Jan 12, 2018 05:33AM UTC | 2 Agent replies | 2 Community replies | How do I?

connection:close And Portswigger CA certificate untrusted by ESET Antivirus

Hello, I have installed burp suite v.1.7.30 on windows 10 and configured Mozilla firefox accordingly. Every time I try to access any website ESET antivirus gives an alert saying "Encrypted Network Traffic, untrusted...

Last updated: Jan 10, 2018 01:51PM UTC | 1 Agent replies | 0 Community replies | How do I?

Android SSL Proxy - Works on browser but not on app

Hello, I'm trying to proxy traffic from an android application to Burp. I've setup the proxy on the mobile device's WiFi settings and imported the Burp CA certificate onto the android device. I'm able to see traffic from...

Last updated: Jan 09, 2018 09:47AM UTC | 1 Agent replies | 0 Community replies | How do I?

Update intruder request according to reponse

Hi All, I'm a burp newbie, sorry if this has been answered before. I am trying to use intruder to brute force a password reset function. The password reset functionality emails a 4 digit number to the email address...

Last updated: Jan 09, 2018 05:46AM UTC | 1 Agent replies | 1 Community replies | How do I?

Understanding sockjs path in Target / Site Map for Vulnerability Scan

Hi, I'm running a Meteor application and can see paths that I've created in my application's router code show up as expected under my website's domain in the `Target -> Site Map` tool within Burp Suite. However, I'm also...

Last updated: Jan 08, 2018 08:23AM UTC | 1 Agent replies | 0 Community replies | How do I?


"><img src=x onerror=prompt(1)>

Last updated: Jan 06, 2018 12:37PM UTC | 0 Agent replies | 0 Community replies | How do I?

Getting Error while updating burpsuit in debian jessy

We are using burpsuit in OS -debian jessy .When we tried to updating burpsuit getting error as shown below An error occurred: java.lang.NoClassDefFoundError: Could not initialize class...

Last updated: Jan 05, 2018 04:38PM UTC | 1 Agent replies | 0 Community replies | How do I?

Get all payloads for scanner?

Hi, Is it possible to get all the payloads from Scanner? And this list should also be categorized per individual issues. Basically, I want to be aware of exactly what payloads will be put in the target requests before...

Last updated: Jan 04, 2018 07:30AM UTC | 1 Agent replies | 1 Community replies | How do I?

Not able to browse websites due to proxy settings

As per the instructions provided, the proxy settings of the Burp Suite shall be configured in the browser as well. I am using Firefox and did the changes under the network tab using the settings sub-tab. Now...

Last updated: Jan 02, 2018 01:50PM UTC | 1 Agent replies | 0 Community replies | How do I?

FireFox Displays: "webpage is not secure", even tough certificates are installed

Dear developers of Burpsuite. I'm using burpsuite community edition, and i want to get the incorrect login cookie credentials of a website. so i opened burpsuite, configured the proxy on, and the firefox...

Last updated: Dec 28, 2017 02:04PM UTC | 2 Agent replies | 0 Community replies | How do I?

Configuration proxy with proxy

Hi, I have problem - i would like to perform penetration testing but service that i need to test requires proxy so i would like to know if i can setup burp to forward request to proxy? Artur

Last updated: Dec 22, 2017 01:29PM UTC | 1 Agent replies | 0 Community replies | How do I?

Authentication in Meteor WebApp

Hello, I have a Meteor based web application that uses Meteor's `accounts-ui` and `accounts-password` packages for login/authentication handling. I've been following this tutorial to get the point-and-click scanner...

Last updated: Dec 20, 2017 11:25AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 290 of 322

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image