The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Need answers for one of the customers.

Basavaraja | Last updated: Jul 23, 2020 08:00AM UTC

Hi, Whether Burp Suite (Enterprise) solution provides Dynamic Application Security Testing for Web Applications and Mobile Applications (Android + iOS Apps)? If Yes, Please share document or URL to support it. For Mobile Application Security Testing, can Burp Suite scan Server Side & Client side both? If Yes, Please share document or URL to support it. As the solution required is complete onsite, does it needs to upload any information in cloud for reporting? Please send me the related inks for the customer to refer. Regards, Basu

Uthman, PortSwigger Agent | Last updated: Jul 23, 2020 09:04AM UTC

Hi Basu, Burp Enterprise supports DAST for most web applications. Unfortunately, mobile testing is out of scope and you will need to use Burp Professional for that. - https://portswigger.net/burp/application-security-testing/dast - https://portswigger.net/burp There is no information uploaded in the cloud.

Basavaraja | Last updated: Jul 23, 2020 11:07AM UTC

Thanks Uthman,for the quick reply.. One more question from customer. Can we use Burp Professional for Server Side & Client side of Mobile Applications both? Also, can we use Burp Professional for DAST (Web) so that we can buy just one product that serves both the purpose (DAST + MAST). Regards, Basu

Uthman, PortSwigger Agent | Last updated: Jul 23, 2020 11:15AM UTC

Hi Basu, You can use Burp Pro for both. Can you please ask the user to complete a free 30-day trial? They can apply for a trial here: https://portswigger.net/requestfreetrial/pro

Basavaraja | Last updated: Jul 23, 2020 11:20AM UTC

Hi, If any links related to the pointer that will help the customer to make decision to by the product. Regards, Basu

Basavaraja | Last updated: Jul 23, 2020 11:23AM UTC

Hi Uthman, Just to reconfirm.. 1. Can we use Burp Professional for Server Side & Client side of Mobile Applications both? 2. Also, can we use Burp Professional for DAST (Web) so that we can buy just one product that serves both the purpose (DAST + MAST). For the above 2 use cases they can use Burp Pro.. Regards, Basu

Uthman, PortSwigger Agent | Last updated: Jul 23, 2020 11:48AM UTC

Hi Basu, That is correct, yes. The mobile testing will likely require manual processes but this can be done in Burp Pro. You can use the application for DAST (Burp Scanner) and MAST. You can find out more information on mobile testing here: https://portswigger.net/burp/documentation/desktop/mobile-testing.

Basavaraja | Last updated: Jul 23, 2020 11:58AM UTC

Thanks a lot Uthman.. This is helping to close the deal.. Regards, BAsu

Uthman, PortSwigger Agent | Last updated: Jul 23, 2020 12:00PM UTC