The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Not able to locate the file

OS: Windows 10 Pro I downloaded Burp Suite Community Edition. When I run the exe file, everything went fine but I couldn't locate the file to open Burp Suite. I tried uninstalling and re-installed it but still couldn't...

Last updated: Oct 27, 2023 07:40AM UTC | 5 Agent replies | 6 Community replies | How do I?

Exam Trouble

I completed 2 labs during the exam but the status on the page didn't change to 3/3 until the time ran out and there was no upload page for the .burp project file I don't know why, can you help me?

Last updated: Oct 27, 2023 07:28AM UTC | 1 Agent replies | 0 Community replies | How do I?

Exploiting Ruby deserialization using a documented gadget chain

Hi I am unable to solve this lab. *I created the base64 encoded payload using the exploit code in this site. https://www.elttam.com/blog/ruby-deserialization/ *I copied the code, changed the required parameters and...

Last updated: Oct 26, 2023 10:37PM UTC | 3 Agent replies | 5 Community replies | How do I?

No user lookup functionality on NoSQL lab

Hi, I'm doing the NoSQL - extract unknown fields lab. And I'm stuck. https://portswigger.net/web-security/nosql-injection/lab-nosql-injection-extract-unknown-fields The description says there's a user lookup...

Last updated: Oct 26, 2023 07:00PM UTC | 1 Agent replies | 1 Community replies | How do I?

Upstream Server Proxy only allow 1 request via Intruder for the whole payload

I am testing to see how Upstream Server Proxy work. Therefore, I created a session Rule to run 2 macros Request at https://ipinfo.io/ip, and https://httpbin.org/ip. For the upstream server, I set up to have a rotating IP...

Last updated: Oct 26, 2023 03:20PM UTC | 2 Agent replies | 1 Community replies | How do I?

XSS with document.location.pathname

Hello I'm kind of a n00b in this do you think this is exploitable And what are your suggestions to do so. <script type="text/javascript"> document.write("<base href='" + document.location.pathname + "' />"); ...

Last updated: Oct 26, 2023 02:52PM UTC | 1 Agent replies | 1 Community replies | How do I?

want to save or export only attack file

Hi, I want to know that how to save only intruder attack file (not save into the project file but save or export only attack file). Is there any way to do this? I'm using Burp professional v2023.3.5. Thank you

Last updated: Oct 26, 2023 12:12PM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp Proxy Timeout

Hello! I met with the problem, where all requests after going through Burp proxy are timeouted, but when I do not use Burp proxy it works in the correct way. I should also mention, that the computer is connected to the...

Last updated: Oct 26, 2023 10:27AM UTC | 2 Agent replies | 1 Community replies | How do I?

302 Found and 302 Moved Temporarily

When I tried to run a payload, I mostly received status code 302 Found or 302 Moved Temporarily which stop the target website from rendering correctly and display a blank page with 302 Found message. This issue is hit and...

Last updated: Oct 26, 2023 10:23AM UTC | 6 Agent replies | 6 Community replies | How do I?

Could not connect to address=(host=127.0.0.1)(port=3306)(type=master) : Socket fail to connect to host:127.0.0.1, port:3306. Connection refused

I'm using Burp Enterprise installed with Helm with the following setup: burp-storage.yaml apiVersion: storage.k8s.io/v1 kind: StorageClass metadata: name: local-storage provisioner:...

Last updated: Oct 26, 2023 10:19AM UTC | 2 Agent replies | 2 Community replies | How do I?

200 w/ Burp, 403 without

Hey y'all, I've hit an issue where doing some POC work in python w/ requests, pycurl libs results in a 403 when hitting an endpoint but when proxying through Burp I get a 200 response. Aside from the obvious things...

Last updated: Oct 26, 2023 07:20AM UTC | 2 Agent replies | 1 Community replies | How do I?

Burpsuite certified Practitioner exam

I'm planning to take the BSCP certification exam. Can I use the Burpsuite professional trial version or do I need to purchase a license?

Last updated: Oct 25, 2023 03:56PM UTC | 1 Agent replies | 0 Community replies | How do I?

Back-off restarting failed container init-enterprise-server-keystore

Hello, I'm trying to install Burp using Helm chart. Everything seems good, but my pods are giving me this message: Back-off restarting failed container init-enterprise-server-keystore in pod...

Last updated: Oct 25, 2023 01:50PM UTC | 2 Agent replies | 8 Community replies | How do I?

Is the GraphQL API available for Burp Suite Pro?

I want to make use of the GraphQL api to retrieve scan results from Burp Suite. I understand from the documentation that the GraphQL api is available for Burp Suite Enterprise, however, I wanted to know if it is also...

Last updated: Oct 25, 2023 01:16PM UTC | 1 Agent replies | 1 Community replies | How do I?

use burp rest api to automate the scan and generate report!

Hi, Currently we run automated security scans with zap by proxying our e2e tests. We want to try out burp suite and pick the best. I was not able to find much support on how to access the rest api documentation and how use...

Last updated: Oct 25, 2023 12:52PM UTC | 6 Agent replies | 5 Community replies | How do I?

Burp Suite isn't working

I have used Burp Suite many years ago, and didn't have issues. Recently I have been trying to get the community version to work but nothing seem to be working regarding intercept. I have tried using the embedded browser...I...

Last updated: Oct 25, 2023 12:23PM UTC | 1 Agent replies | 0 Community replies | How do I?

burp intruder numbers problem

Hi I want to use the intruder section in burp suit. When I set the payload type to numbers and select the numbers 1 to 1000 and then start attack, in the opened window in the payload column, instead of the numbers 1...

Last updated: Oct 25, 2023 09:24AM UTC | 1 Agent replies | 0 Community replies | How do I?

I imported a certificate, but the certificate verification seems to have failed.

I have updated to a new burp version and am having trouble verifying the certificate. I have regenerated the certificate at burp and performed this process multiple times with no improvement. The version of burp is:...

Last updated: Oct 24, 2023 02:17PM UTC | 1 Agent replies | 1 Community replies | How do I?

HTTPS/HSTS errors after certificate import

Hello, I am currently trying to use burp suite pro v2020.08 to intercept traffic for a website which is using HSTS (google.com). I've installed the Burp CA Certificate in the firefox browser, however navigating to...

Last updated: Oct 24, 2023 08:48AM UTC | 2 Agent replies | 2 Community replies | How do I?

not supporting HSTS

i am trying hard to access sites with hsts enabled via burp proxy. did installed the firefox older version 3.6.25 but not working properly . nothing is displayed on screen keep on saying wrong certificate . i am facing...

Last updated: Oct 24, 2023 08:48AM UTC | 8 Agent replies | 16 Community replies | How do I?

Page 47 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image