The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp Rest API - Launch a simple crawling

Hey.. i'm trying to start a simple crawl WITHOUT AUDIT CHECKS. I've saved my crawl config in the Configuration Library named as crawling_1, then.. curl -vgw "\n" -X POST 'http://127.0.0.1:1337/xxxxxxx/v0.1/scan' -d...

Last updated: Aug 21, 2023 01:50PM UTC | 2 Agent replies | 2 Community replies | How do I?

Help with Custom Extension / Macro Involving Auth Tokens in URL

I am trying to perform some automated scans of a web application that utilizes a JWT in the URL, which has an expiration date of 10 minutes. The JWT always appears at the end: /api/v2/fakeendpoint/<JWT> I have seen...

Last updated: Aug 21, 2023 01:29PM UTC | 1 Agent replies | 0 Community replies | How do I?

Explore Exciting Opportunities in Colombia and Malaysia: Travel, Earnings, and Lottery Adventures Await!

Are you seeking the perfect blend of travel, earning potential, and thrilling lottery experiences? Look no further than Colombia and Malaysia! These two vibrant countries offer a unique combination of cultural richness,...

Last updated: Aug 21, 2023 12:19PM UTC | 0 Agent replies | 0 Community replies | How do I?

Issues list

Hi all. I accidentally .db file instead of a .burp project with "ip, url, http method, , request raw, response raw, time, http status" columns. Can I get a list of issues based on this data?

Last updated: Aug 21, 2023 10:01AM UTC | 1 Agent replies | 0 Community replies | How do I?

API scanning using dastardly

Hi. I am unable to scan api endpoint using api defination. SCRIPT > - task: CmdLine@2 displayName: Run DAST scan with dastardly inputs: targetType: 'inline' script: | docker...

Last updated: Aug 21, 2023 08:09AM UTC | 1 Agent replies | 0 Community replies | How do I?

Dastardly - Restrict URLs

Hey, Is there anyway I can add to/restrict URLs for the Dastardly scanner? There are some URLs (e.g. the CMS login page) I would also like scanned which aren't on my site to crawl. Additionally, I don't need it to scan...

Last updated: Aug 21, 2023 08:06AM UTC | 1 Agent replies | 0 Community replies | How do I?

Not getting mark as complete checkbox

I'm not getting tracked of my progress of reading materials. Although I had read that. Also, not getting that checkbox to mark my reading materials progress.

Last updated: Aug 19, 2023 07:26AM UTC | 1 Agent replies | 1 Community replies | How do I?

Make HTTP Request from 127.0.0.1 (localhost)

I am using Reactor to assist with answering some questions regards the sending of HTTP requests and one question that has me stumped is sending a request from source 127.0.0.1. If anyone can point me in the right...

Last updated: Aug 18, 2023 09:51AM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp Suite Professional is not intercepting any request

Hello Burp, When I launch Burp Pro and click on Proxy ==> Open browser, and navigate to https://portswingger.net, nothing happens in the intercept tab. Burp is not intercepting any request and the built-in browser...

Last updated: Aug 18, 2023 08:57AM UTC | 3 Agent replies | 3 Community replies | How do I?

TypeError: Cannot read properties of undefined

I'm getting this error when i click on the "Schedule Scans" button, the page still loading but after a minutes return error bellow: Whoops - something bad happened TypeError: Cannot read properties of undefined (reading...

Last updated: Aug 17, 2023 09:04AM UTC | 1 Agent replies | 0 Community replies | How do I?

"Burp Browser is not available in this execution mode" I get this when i try to launch the Burp browser. What does this mean and how do i fix it?

"Burp Browser is not available in this execution mode" I get this when i try to launch the Burp browser. What does this mean and how do i fix it?

Last updated: Aug 16, 2023 03:13PM UTC | 1 Agent replies | 1 Community replies | How do I?

View Cached pages when using built-in Chromium

I am on Window and I am using Burp's Chromium browser to view test. The page I am testing caches some pages which contain confidential data. I wanted to view those files, but on...

Last updated: Aug 16, 2023 01:20PM UTC | 1 Agent replies | 1 Community replies | How do I?

Turbo Intruder Race.py script missing?

Hello, Turbo Intruders example scripts use to have a script called examples/race.py which I can no longer find? How do I run Turbo Intruder without any wordlists? I just want to send the same request?

Last updated: Aug 15, 2023 07:27PM UTC | 1 Agent replies | 1 Community replies | How do I?

problème avec lab #5

L'e-mail de la victime dans lab #5 n'est pas modifié dans lorsque je soumets la demande avec la clé et le jeton CSRF du hackeur (carlos). j'ai vérifié que j'utilisais un nouveau jeton CSRF. J'ai suivi les instructions de...

Last updated: Aug 15, 2023 02:40PM UTC | 2 Agent replies | 3 Community replies | How do I?

Inquiry about CLI Usage in Burp Suite Professional and Enterprise

Hello Burp Suite Community, I hope you're all doing well. I'm currently exploring the capabilities of Burp Suite for security testing and I'm interested in utilizing the command-line interface (CLI) feature for some of...

Last updated: Aug 15, 2023 12:21PM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab: SQL injection with filter bypass via XML encoding in Python

Hi, I am currently doing Lab: SQL injection with filter bypass via XML encoding (https://portswigger.net/web-security/sql-injection/lab-sql-injection-with-filter-bypass-via-xml-encoding) and I am struggling to solve this...

Last updated: Aug 15, 2023 11:03AM UTC | 1 Agent replies | 0 Community replies | How do I?

How to reproduce following POC of dom based open redirection Vulnerability Flagged by burp suite scan

Data is read from location.pathname and passed to xhr.open. The following value was injected into the source: /////hwrylpu593%27%22%60'%22/hwrylpu593/%3E%3Chwrylpu593//%3Egktz6gq8qs& The previous value reached the sink...

Last updated: Aug 15, 2023 10:51AM UTC | 1 Agent replies | 0 Community replies | How do I?

Burp Suite v2023.9.1 + rooted android 7 and 8 certificate unknown

Hi Community, I want to see the http requests instagram apk on android is doing. We are part of the Whitehat Instagram / Facebook Developers which can turn off app cert pinning and tls1.3 from the official...

Last updated: Aug 15, 2023 10:36AM UTC | 1 Agent replies | 0 Community replies | How do I?

REPEATER REPONSE MANIPULATION !

In Repeater, we can edit request and see the response, but same way can we edit response and see output? Please illustrate with screenshots and mail me. Thank you!

Last updated: Aug 15, 2023 10:26AM UTC | 2 Agent replies | 1 Community replies | How do I?

Unable to Connect to PortSwigger Labs or Forum through BurpBrowser

I updated to the most recent version of Burp Suite, when trying to access any of the labs or the Forum.PortSwigger.net website when using the Burp Browser I am given an error: ERR_TIMED_OUT I am able to connect to the...

Last updated: Aug 15, 2023 07:28AM UTC | 4 Agent replies | 2 Community replies | How do I?

Page 56 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image