Burp Suite User Forum

Create new post

To reset all my progress labs

I want to solve again all lab so reset my all lab that i have solved

Last updated: Sep 27, 2024 07:34AM UTC | 1 Agent replies | 0 Community replies | How do I?

Issues on the proposed solution to Lab: Forced OAuth profile linking

I have tried both iframe and img tabs in burp's browser and others. I have tried switching to incognito, but that doesn't help either. I have tried multiple ways to deliver the payload, but it seems like the user doesn't...

Last updated: Sep 26, 2024 09:30PM UTC | 0 Agent replies | 1 Community replies | How do I?

Lab: HTTP request smuggling, basic TE.CL vulnerability

Hello! Can you help me understand one interesting moment in this lab? In this lab, smuggling request will be succesful. POST / HTTP/1.1 Host: 0a5e00970446a1b38002d12d005f0084.web-security-academy.net Sec-Ch-Ua:...

Last updated: Sep 26, 2024 05:26PM UTC | 2 Agent replies | 1 Community replies | How do I?

Issue with Collablorator

Below mentioned is the health check of my burp collaborator, I am using v2024.7.6. Initiating health check Server address resolution Success Server HTTP connection Error Server HTTPS connection (trust...

Last updated: Sep 26, 2024 02:47PM UTC | 1 Agent replies | 0 Community replies | How do I?

cannot access labs

Burp Suite Community Edition Error Could not create new HTTP/2 connection

Last updated: Sep 26, 2024 09:57AM UTC | 2 Agent replies | 1 Community replies | How do I?

What can i do to resolve this issue "Secure Connection Failed"

I am using firefox in kali linux,i have imported my certificates and also configured my browser...all went well yesterday i was able to accesse both HTTP and HTTPS sites..but all of a sudden when i used it today it shows the...

Last updated: Sep 26, 2024 07:45AM UTC | 7 Agent replies | 8 Community replies | How do I?

no more activations allowed for this license

Hi team, could you please help on this issue.

Last updated: Sep 26, 2024 07:42AM UTC | 1 Agent replies | 0 Community replies | How do I?

API Scans

Hi everyone, how are you? I trying to scan API in my environment, and I have a question. I've already run scans on a few different APIs, and I haven't gotten any significant results from any of them, and the scans only...

Last updated: Sep 25, 2024 01:06PM UTC | 1 Agent replies | 0 Community replies | How do I?

Exploiting an API endpoint using documentation Lab Trouble

I am trying to complete the first exercise in this lab and whenever I try to update the email I get the error - `undefined: Malformed URL: query only supported with GET (undefined)` Is something wrong with my burp...

Last updated: Sep 25, 2024 07:59AM UTC | 1 Agent replies | 0 Community replies | How do I?

Cloudflare issue

I am having an issue when proxying traffic between a mobile app and a back-end server that is behind Cloudflare. The error is: 'The client failed to negotiate a TLS connection to x.x.x.x:8080: Remote host terminated the...

Last updated: Sep 25, 2024 07:49AM UTC | 2 Agent replies | 1 Community replies | How do I?

Is there some different configurations required for intercepting Flutter and ARM based mobile application

I'm not able to intercept the traffic of the ARM android application, however i can clearly see traffic passing via wireshark. The application does not have ssl pinning and burp is properly configured with emulator as i'm...

Last updated: Sep 25, 2024 05:51AM UTC | 1 Agent replies | 1 Community replies | How do I?

Flutter Based Android Application Traffic Interception

Can you give a suggestion that how can I intercept the traffic for flutter based android application with burpsuite. Note that It doesn't have SSL Implementation in the application. Please suggest me a solution for...

Last updated: Sep 25, 2024 05:51AM UTC | 1 Agent replies | 1 Community replies | How do I?

How to use burp with flutter based Android applications

Any tips while pen-testing Flutter based Android apps? Since it ignores system proxy and user/system CA certificates you cannot use burp suite easily.

Last updated: Sep 25, 2024 05:50AM UTC | 1 Agent replies | 1 Community replies | How do I?

unable to access The web application hackers handbook link

hello everyone, I am reading and practicing from the portswigger academies The web application Hackers handbook. If you are a old user of portswigger academy you know that in early time the url to access this was like...

Last updated: Sep 23, 2024 01:22PM UTC | 1 Agent replies | 0 Community replies | How do I?

I wonder why I'm not getting any contact from Burp Swigger

I sent a request email for a free trial of Burp Pro, but I haven’t received a reply within 24 hours. I submitted and requested the Burp free trial several times on this page https://portswigger.net/burp/pro/trial, but I...

Last updated: Sep 23, 2024 01:08PM UTC | 1 Agent replies | 0 Community replies | How do I?

No more activations allowed for this license

Hi!! Unfortunately I have had to reinstall my pc on several occasions and now when I try to install burp suite, I get the error "No more activations allowed for this license" Could you help me...

Last updated: Sep 23, 2024 12:07PM UTC | 1 Agent replies | 0 Community replies | How do I?

Return 500 during intruder attack with Lab: Exploiting NoSQL operator injection to extract unknown fields

Hello, When doing this lab : https://portswigger.net/web-security/nosql-injection/lab-nosql-injection-extract-unknown-fields The intruder attack return error 500 for each request with this payload...

Last updated: Sep 23, 2024 12:05PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp2 URL exclusion for scan, but not for session

For Burp2 and Burp EE - how do I exclude the URL for scanning, but not for crawling part? That is, the login is taken care of by 3rd party authentication mechanism located in external domain. Example: Test scope URL:...

Last updated: Sep 23, 2024 11:55AM UTC | 3 Agent replies | 4 Community replies | How do I?

not getting expected responses

i am doing brute force labs but i am not receiving expected response from last 2 or 3 labs currently i am doing " Password brute-force via password change " this lab and Sec-Fetch-Site: same-origin Sec-Fetch-Mode:...

Last updated: Sep 23, 2024 09:10AM UTC | 1 Agent replies | 0 Community replies | How do I?

Hitting ERR_BLOCKED_BY_ORB when trying to intercept my local server

I'm currently using Burp Suite Community Edition, and im Hitting ERR_BLOCKED_BY_ORB on some of my .js request when trying to load my application then the page just become blank. I would greatly appreciate any help or advice...

Last updated: Sep 23, 2024 09:03AM UTC | 3 Agent replies | 3 Community replies | How do I?

Page 4 of 330

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image