The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Active scan on API with HTTP/2

Is there any way to perform active scans on an API for a server that uses HTTP2 only? I currently have no problem with the Repeater making HTTP2 requests, but if I send the request for an active scan, HTTP2 is not used or...

Last updated: Feb 07, 2023 04:58PM UTC | 1 Agent replies | 0 Community replies | How do I?

IS NOT POSSIBLE TO CONNECT A ADDITIONAL SCAN MACHINE

Hello everyone, I'm trying to add a new machine (scan machine) in my Burp Enterprise, however i get the message "Cannot connect to database" I already have others scan machines, but this one I'm trying to configure i...

Last updated: Feb 07, 2023 01:33PM UTC | 1 Agent replies | 1 Community replies | How do I?

Crawling failed after login

Hi, I have used recorded sequence to login to a website to scan it. After crawling started, the debug section under event log showing a message as '0 new location found after login'. What is the reason for this and How to...

Last updated: Feb 07, 2023 10:21AM UTC | 2 Agent replies | 1 Community replies | How do I?

Why is the login failing despite giving proper credentials in Burp Enterprise Edition? Is there any extra setting required?

Hi, We are evaluating Burp Enterprise Edition to help us cover some valuable amount of security testing as a part of our CI. Before anything else, I tried to set up Burp Enterprise Edition and gave the URL of our...

Last updated: Feb 07, 2023 10:03AM UTC | 5 Agent replies | 5 Community replies | How do I?

CSRF where token is duplicated in cookie

Trying to solve this lab and the lab before it my code works in the browser but not in the exploit server: ```<html> <body> <h1>Hey</h1> <iframe style="display:none" name="csrf-iframe"></iframe> ...

Last updated: Feb 07, 2023 07:46AM UTC | 1 Agent replies | 0 Community replies | How do I?

Automated scan does not recognize Javascript

Hello, I would like to perform an automated scan with Burp Professional and when I run it, I get the message: "We're sorry but XYZ doesn't work properly without JavaScript enabled. Please enable it to continue." As far...

Last updated: Feb 06, 2023 05:25PM UTC | 1 Agent replies | 0 Community replies | How do I?

Does Burp Professional ".exe" read "BurpSuitePro.vmoptions" file ?

Hello, I'd like to add custom JVM arguments, in particular: -Djdk.tls.maxHandshakeMessageSize=262144 for TLS handshake. I've added it to BurpSuitePro.vmoptions but it seems that starting burp from standalone exe...

Last updated: Feb 06, 2023 04:45PM UTC | 2 Agent replies | 1 Community replies | How do I?

Changing Subscription to a different existing account

Greetings, I recently purchased 4 professional licenses mapped to an account. However I want to switch over the ownership and the master account to different account which had previously expired subscription. Every time I...

Last updated: Feb 06, 2023 01:27PM UTC | 1 Agent replies | 0 Community replies | How do I?

Pretty sure its broken

I tried to do the Lab: SQL injection attack, listing the database contents on non-Oracle databases for a long time now. I don't think the updated username_table and columns are right. I am 100% sure my syntax is...

Last updated: Feb 06, 2023 11:27AM UTC | 1 Agent replies | 0 Community replies | How do I?

Install Burpsuirt Community Edition on ubunto Server

Dear Team , Kindly note that i have create vm on oracle cloud with 24 RAM and 200 HD and tried to install Burpsuirt Community Edition version , However I'm facing the below error sudo...

Last updated: Feb 06, 2023 11:02AM UTC | 1 Agent replies | 0 Community replies | How do I?

Showing response in browser link error

When I click show response in browser it generates a link but when I open it, it downloads a file named [v1_GetHints.json]. Now I don't know what to do with that file.

Last updated: Feb 06, 2023 10:55AM UTC | 2 Agent replies | 1 Community replies | How do I?

DOM Invader in external Chrome browser

I am using Burp Suite Professional, in a Kali VM which is running on a M1 MacBook Pro. Therefore I have to install it using the JAR file, which does not support launching an in-built/default Chrome instance. Is it still...

Last updated: Feb 06, 2023 09:41AM UTC | 2 Agent replies | 1 Community replies | How do I?

scan in community

if u cant do a basic scan in community, wots the point

Last updated: Feb 06, 2023 09:14AM UTC | 1 Agent replies | 0 Community replies | How do I?

HTTP request smuggling, confirming a TE.CL vulnerability via differential responses

Could you guys explain to me why the Content-Length of the second request needs to be 15? I see that the values 12 and 13 work, but if I send 10 it does not. I thought that any greater value than the body of the request...

Last updated: Feb 02, 2023 02:40PM UTC | 1 Agent replies | 0 Community replies | How do I?

SSRF via flawed request parsing

This lab requires users to brute force the IP in the host header to find the admin panel. My issue is that, even when following the solution and community solutions, intruder is not able to brute force the IP. Target:...

Last updated: Feb 02, 2023 11:42AM UTC | 1 Agent replies | 0 Community replies | How do I?

Lab: SameSite Strict bypass via client-side redirect

Hello! I was studying about SameSite restrictions in the Academy. However, a question mark has formed in my mind when I was trying to solve the lab "SameSite Strict bypass via client-side redirect". In the step 5 of...

Last updated: Feb 02, 2023 11:37AM UTC | 1 Agent replies | 0 Community replies | How do I?

Unable to upload the license to activate Burp Enterprise edition

Unable to upload the license to activate Burp Enterprise edition. Getting error as "There was problem checking your license". I have enabled proxy server before activation. How to fix this issue.

Last updated: Feb 01, 2023 11:13AM UTC | 2 Agent replies | 1 Community replies | How do I?

Help regarding lab solutions despite following the steps

Hi, For some labs even if I follow the correct steps mentioned in the solution I get 404 or server error and the lab doesn't get solved. Please look into it

Last updated: Feb 01, 2023 10:08AM UTC | 1 Agent replies | 0 Community replies | How do I?

Delete my account

Dear Concern, I request you to please delete my account.

Last updated: Feb 01, 2023 09:59AM UTC | 2 Agent replies | 2 Community replies | How do I?

Custom Extension - How to programmatically call the built-in Chrome browser?

My apologies if this has been asked already but I haven't been able to find an answer anywhere. My question is: Is there an API method that I can call from my custom Burp extension to send URLs to the Burp built-in Chrome...

Last updated: Feb 01, 2023 09:38AM UTC | 1 Agent replies | 0 Community replies | How do I?

Page 82 of 332

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image