Burp Suite User Forum

Create new post

certificate pinning issue

Hi, We are testing an application which has certificate pinning, but the debug version includes the fingerprint of the charles server of the dev team. We have received this certificate in pfx format, can import into burp...

Last updated: Feb 07, 2018 03:55PM UTC | 3 Agent replies | 2 Community replies | How do I?

Penetration tests on standalone app using Burp

Hi , I am required to perform active PEN tests on standalone app using Burp. Need info on how to intercept the requests.. Can you please guide me on this ? Rds, Garry

Last updated: Feb 07, 2018 09:07AM UTC | 1 Agent replies | 0 Community replies | How do I?

Automate the scanning process with multiple or all types of known attacks over my web application

Automate the scanning process with multiple or all types of known attacks over my web application. Currently when I run the scanner and attack, only the server config issues are listed in reports and the individual...

Last updated: Feb 06, 2018 04:14PM UTC | 1 Agent replies | 0 Community replies | How do I?

Connection reset error or 502 bad gateway

I frequently get connection reset error or 502 Bad gateway error while i crawl through a website whereas the initial requests are 200. All the settings and certificates are in place. Not sure on what other settings to make? ...

Last updated: Feb 06, 2018 01:30PM UTC | 1 Agent replies | 0 Community replies | How do I?

http://burp doesn't show download CertificateCA

Hi, I had already follow instruction to configure my browser with burp proxy (127.0.0.1:8080) I had already active burp and make sure the proxy is on (Checked) (127.0.0.1:8080) But when i access http://burp to download...

Last updated: Feb 05, 2018 08:20AM UTC | 1 Agent replies | 0 Community replies | How do I?

Create a simple Burp Extension to save scrolled URLs to a txt file

Hi, I'm trying to learn how to create a burp extension. As a first step I'm trying to create an extension to save scrolled URLs to a text file. Is there any guide can I use. Thanks.

Last updated: Feb 05, 2018 08:18AM UTC | 1 Agent replies | 0 Community replies | How do I?

Cross-site scripting (DOM-based)

Burp has created two different tentative DOM XSS issues with this description: "The application may be vulnerable to DOM-based cross-site scripting. Data is read from location and passed to $() via the following...

Last updated: Jan 30, 2018 07:42AM UTC | 2 Agent replies | 1 Community replies | How do I?

Locked due to many failed login attempts as soon as i scan my application

Issue 1: My application(https://test2.tstraining.com/) is getting locked due to many failed login attempts as soon as i scan my application. Am i sending bunch other invalid passwords ?? I see below article. I don't...

Last updated: Jan 25, 2018 10:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Viewing Issues

After running a scan using Community Version v1.7.30 in free mode, I do not see a the Issues tab under Target >> Site Map. After looking at posted screenshots, I see a set of tabs above the Request | Response tabs. I do not...

Last updated: Jan 23, 2018 04:19PM UTC | 1 Agent replies | 0 Community replies | How do I?

Support

How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.

Last updated: Jan 22, 2018 04:12PM UTC | 1 Agent replies | 0 Community replies | How do I?

Support

How to remove repeating same letters when brute forcing. Like the program won't make passwords llike aaaaaa or bbcghe because the letters repeat.

Last updated: Jan 22, 2018 03:31PM UTC | 0 Agent replies | 0 Community replies | How do I?

Remote host connection closed during handshake

Hi , Burp is not intercepting traffic when I am accessing app via company n/w with proxy However, when I am connected to my home n/w ( no proxy) I am able to intercept in Burp. Can you please advise...

Last updated: Jan 22, 2018 11:38AM UTC | 3 Agent replies | 3 Community replies | How do I?

Expression Language Injection Syntax

I'm trying to improve my understanding of expression language (EL) injections. The following injections were created by Burp...

Last updated: Jan 19, 2018 04:18PM UTC | 3 Agent replies | 1 Community replies | How do I?

Unable to use Burp with proxy

Setting my Firefox proxy server to 127.0.0.1:8080 for all protocols disallows me from connecting to any website at all. Error message: https://gyazo.com/dba7c96b3dd6920b33f1ccf2810b7826 Not only that, but the HTTP...

Last updated: Jan 19, 2018 08:44AM UTC | 2 Agent replies | 1 Community replies | How do I?

Restore installed extensions

Hey, Is it possible to install a selected number of extensions from BAppStore and restore them on Burp restart and new project creation? It is tedious to reinstall extensions everytime I start bounting on a new scope.

Last updated: Jan 12, 2018 05:33AM UTC | 2 Agent replies | 2 Community replies | How do I?

connection:close And Portswigger CA certificate untrusted by ESET Antivirus

Hello, I have installed burp suite v.1.7.30 on windows 10 and configured Mozilla firefox accordingly. Every time I try to access any website ESET antivirus gives an alert saying "Encrypted Network Traffic, untrusted...

Last updated: Jan 10, 2018 01:51PM UTC | 1 Agent replies | 0 Community replies | How do I?

Android SSL Proxy - Works on browser but not on app

Hello, I'm trying to proxy traffic from an android application to Burp. I've setup the proxy on the mobile device's WiFi settings and imported the Burp CA certificate onto the android device. I'm able to see traffic from...

Last updated: Jan 09, 2018 09:47AM UTC | 1 Agent replies | 0 Community replies | How do I?

Update intruder request according to reponse

Hi All, I'm a burp newbie, sorry if this has been answered before. I am trying to use intruder to brute force a password reset function. The password reset functionality emails a 4 digit number to the email address...

Last updated: Jan 09, 2018 05:46AM UTC | 1 Agent replies | 1 Community replies | How do I?

Understanding sockjs path in Target / Site Map for Vulnerability Scan

Hi, I'm running a Meteor application and can see paths that I've created in my application's router code show up as expected under my website's domain in the `Target -> Site Map` tool within Burp Suite. However, I'm also...

Last updated: Jan 08, 2018 08:23AM UTC | 1 Agent replies | 0 Community replies | How do I?

"><svg/onload=prompt(1)>

"><img src=x onerror=prompt(1)>

Last updated: Jan 06, 2018 12:37PM UTC | 0 Agent replies | 0 Community replies | How do I?

Page 298 of 330

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image