The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How to use functional testing browser traffic to identify security vulnerabilities in Burp Suite?.

TIRUKODIKAVAL | Last updated: Dec 01, 2022 08:29PM UTC

We want to use the browser traffic generated for application functional testing performed by tester with Burp suite tool to identify security issues. I understand that we can use active scan or spider option to automatically scan the app. Since the app constantly undergoes changes, we want to try to place a burp suite agent that can collect the browser traffic and use it in Burp suite tool. If it is supported by Burp, we need documentation/ steps to perform this activity.

Liam, PortSwigger Agent | Last updated: Dec 02, 2022 07:27AM UTC

Hi Sundararaman Are you looking for something like this? - https://portswigger.net/support/using-burp-with-selenium

TIRUKODIKAVAL | Last updated: Dec 06, 2022 08:49PM UTC

Hello Thanks for the update. Yes. We also want to know if we can place any burp agent in tester machine so that when they manually perform functional testing, it can capture/record the traffic and create a file. We can use recorded traffic data file in Burpsuite tool and perform active scan on the recorded traffic.

Liam, PortSwigger Agent | Last updated: Dec 07, 2022 07:35AM UTC

Thanks for following up. To clarify, what do you mean by Burp Agent? Is this an instance of Burp Suite Professional?

TIRUKODIKAVAL | Last updated: Dec 07, 2022 08:06PM UTC

yes. We are using Burp professional edition. We would like to place burp agent/ traffic recorder that will capture the browser traffic performed by testing team. We don't want to install burp suite software in tester machine. For example, Appscan enterprise has a feature traffic recorder that you can use to record browser traffic which will be saved as DAST config file and there is no need for tester to install appscan standard tool. Security team will use the config file and import it in Appscan standard tool to perform scan. We want to try this option with Burpsuite as well.

Liam, PortSwigger Agent | Last updated: Dec 08, 2022 08:06AM UTC