Burp Suite User Forum
Hi, We are testing an application which has certificate pinning, but the debug version includes the fingerprint of the charles server of the dev team. We have received this certificate in pfx format, can import into burp...
Hi , I am required to perform active PEN tests on standalone app using Burp. Need info on how to intercept the requests.. Can you please guide me on this ? Rds, Garry
Automate the scanning process with multiple or all types of known attacks over my web application. Currently when I run the scanner and attack, only the server config issues are listed in reports and the individual...
I frequently get connection reset error or 502 Bad gateway error while i crawl through a website whereas the initial requests are 200. All the settings and certificates are in place. Not sure on what other settings to make? ...
Hi, I had already follow instruction to configure my browser with burp proxy (127.0.0.1:8080) I had already active burp and make sure the proxy is on (Checked) (127.0.0.1:8080) But when i access http://burp to download...
Hi, I'm trying to learn how to create a burp extension. As a first step I'm trying to create an extension to save scrolled URLs to a text file. Is there any guide can I use. Thanks.
Burp has created two different tentative DOM XSS issues with this description: "The application may be vulnerable to DOM-based cross-site scripting. Data is read from location and passed to $() via the following...
Issue 1: My application(https://test2.tstraining.com/) is getting locked due to many failed login attempts as soon as i scan my application. Am i sending bunch other invalid passwords ?? I see below article. I don't...
After running a scan using Community Version v1.7.30 in free mode, I do not see a the Issues tab under Target >> Site Map. After looking at posted screenshots, I see a set of tabs above the Request | Response tabs. I do not...
How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.
How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.
Hi , Burp is not intercepting traffic when I am accessing app via company n/w with proxy However, when I am connected to my home n/w ( no proxy) I am able to intercept in Burp. Can you please advise...
I'm trying to improve my understanding of expression language (EL) injections. The following injections were created by Burp...
Setting my Firefox proxy server to 127.0.0.1:8080 for all protocols disallows me from connecting to any website at all. Error message: https://gyazo.com/dba7c96b3dd6920b33f1ccf2810b7826 Not only that, but the HTTP...
Hey, Is it possible to install a selected number of extensions from BAppStore and restore them on Burp restart and new project creation? It is tedious to reinstall extensions everytime I start bounting on a new scope.
Hello, I have installed burp suite v.1.7.30 on windows 10 and configured Mozilla firefox accordingly. Every time I try to access any website ESET antivirus gives an alert saying "Encrypted Network Traffic, untrusted...
Hello, I'm trying to proxy traffic from an android application to Burp. I've setup the proxy on the mobile device's WiFi settings and imported the Burp CA certificate onto the android device. I'm able to see traffic from...
Hi All, I'm a burp newbie, sorry if this has been answered before. I am trying to use intruder to brute force a password reset function. The password reset functionality emails a 4 digit number to the email address...
Hi, I'm running a Meteor application and can see paths that I've created in my application's router code show up as expected under my website's domain in the `Target -> Site Map` tool within Burp Suite. However, I'm also...
"><img src=x onerror=prompt(1)>
Page 298 of 330
Your source for help and advice on all things Burp-related.