Name is required.
Email address is required.
Invalid email address
Answer is required.
Exceeding max length of 5KB

Burp Overlay Menus no longer Working on Fedora 26

Norman H Jan 31, 2018 11:09AM UTC


with Burp version 1.7.31 the overlay menus (like the proxy filter menu) are instantly closing as soon as one clicks on it. It is confirmed working with Burp version 1.7.27.

Oracle java version: 1.8.0_162-b12
run command: java -Dawt.useSystemAAFontSettings=on -Dsun.java2d.d3d=false -Dsun.java2d.xrender=false -jar

best regards,

Liam Tai-Hogan Feb 01, 2018 11:48AM UTC Support Center agent

Have you tried using the latest version of Oracle Java?

Or using the platform installer version of Burp Suite?

Norman H Feb 04, 2018 02:33PM UTC

version 1.8.0_162-b12 is already the latest version (as Java 9 is not yet fully supported). A colleague of mine seems to have the exact opposite problem with the latest version (menus can't be closed anymore). The functionality worked perfectly till version 1.7.28 and stopped working with version 1.7.29

I tried OpenJDK 8 latest version, Oracle JDK 8 latest version and the packaged jre version. None work with version 1.7.29 or greater.

best regards,

Liam Tai-Hogan Feb 05, 2018 11:04AM UTC Support Center agent

Thanks for the additional information. We’ll try and reproduce this issue.

Norman H Feb 06, 2018 04:47PM UTC
If you try to search something in the repeater tab for example and burp trys to show the suggestion box, for recent search terms, that is a window for example, that doesn't close till burp is closed. This already affects 1.7.27.

Liam Tai-Hogan Feb 07, 2018 04:07PM UTC Support Center agent

Thanks for keeping us updated.

We’re still unable to reproduce this in our testing. Currently using Fedora 26 with the installer version of Burp Suite (bundled with 1.8.0_112-b15).

We’ll try using 1.8.0_162-b12. In the meantime, you could try using the linux installer version of Burp Suite.

Norman H Feb 08, 2018 03:23PM UTC
I'm using Qubes as main OS. So fedora runs inside a XEN VM. I've already tried the installer version and it had the same problems. (Under windows it works fine).

I'll try to get it to reproduce in a VirtualBox image during the weekend. Hopefully that works, to help you reproduce it.

Thanks for the update!

Norman H Feb 12, 2018 12:58PM UTC
Ok so far the difference seems to be, that on my system a new window (with taskbar item) is created when I open a submenu. In a VM with virtualbox and fedora, the window is opened "within" the application and no new application window is registered.

Sometimes the window stays open (but after closing can't be opened again ...). Maybe it is some kind of focus check, that immediately closes the window again?

If I click the proxy bar on a normal system for example, the window always closes and opens again. Maybe that mechanism doesn't work here and instead of staying open, it just closes again...

Liam Tai-Hogan Feb 12, 2018 03:06PM UTC Support Center agent

Thanks for the additional information Norman. We’ve made a note to investigate this further if we manage to reproduce it during testing.

Jan S May 22, 2018 03:06PM UTC
I have the exact same issues as Norman H and also use the virtualization desktop Qubes OS (Release 3.2). I guess it is some distribution specific configuration of Qubes (e.g. window manager configuration). Any help would be great!

Liam Tai-Hogan May 24, 2018 01:06PM UTC Support Center agent

Thanks for the report Jan. We’ll have another go and reproducing the issue.

Liam Tai-Hogan Jun 07, 2018 03:03PM UTC Support Center agent

Norman. We’ve been unable to reproduce the issue. It would be a great help if you could help us narrow down the exact version change when the issue occurred.

You mentioned there is no issue with 1.7.27 and the issue occurs from 1.7.31 onwards? Would it be possible to try out 1.7.28, 1.7.29 and 1.7.30?

Norman H Jun 12, 2018 12:21PM UTC

The issue started to appear in Burp 1.7.29. Everything works fine in Version 1.7.28.

And I can confirm that it is a Qubes specific issue with any recent Java version.
I have not been able to reproduce it on any other system (tried windows 7 and windows 10, I tried running multiple distros with different window managers in a VM on windows and live directly on the laptop and with windows VMs under linux).

It not only affects burp, the Intellij Rider has the same problem.

I also tried multiple different linux version within the qubes VM itself (fedora 24 - 27) and debian 8 and 9, same result.

It must an issue with how the sub windows are opened programmatically in the java user code. I also tried Oracle JDK 7,8,9 with different sub versions and OpenJDk to no avail.

Norman H Jun 12, 2018 12:46PM UTC
I also opened a issue with qubes now:

Norman H Jun 13, 2018 09:31AM UTC
Hm with intellij it appears to be a regular issue:

Liam Tai-Hogan Jun 13, 2018 10:26AM UTC Support Center agent

Thanks for the information and updates Norman. We made a change from 1.7.28 to 1.7.29 to address another issue, which may have inadvertently triggered this issue.

We don’t think this is a bug in our software so we’re going to monitor the situation and take another look if it isn’t fixed long term.

Norman H Jun 13, 2018 01:01PM UTC
Qubes refused to fix it and already closed it with not our bug. So only way this is going to be fixed is, if burp addresses it in the java code itself.

Paul Johnston Jun 14, 2018 02:09PM UTC Support Center agent

Hi Norman,

Thanks for letting us know. We are going to investigate the relevant code in Burp to what we had in 1.7.28. Unfortunately, because we can’t replicate the issue ourselves, we can’t confirm the fix has worked. We’ll let you know when we make progress.

Norman H Jun 21, 2018 04:21PM UTC
Always happy to test unstable builds etc. Just drop me a mail!

Liam Tai-Hogan Jun 29, 2018 10:02AM UTC Support Center agent

Just to let you know that this issue should be fixed in today’s release (1.7.35). Thanks for your feedback and please let us know if you run into any other problems.

Norman H Jul 03, 2018 07:14AM UTC
Unfortunately, the release 1.7.35 has the same behaviour.

Liam Tai-Hogan Jul 03, 2018 10:44AM UTC Support Center agent

It looks like the fix worked for other versions of Linux, but not Qubes. We’ll continue to investigate this issue. In the meantime we’d recomend using another OS.

Norman H Jul 03, 2018 12:04PM UTC
Pretty hard to switch to another OS just so, after you migrated to Qubes OS (its not like switching linux distros, more like switching from windows to linux or macos to linux regarding the effort) ;)
I'll stick with version 1.7.28 for now :)

Simon Aug 21, 2018 03:23PM UTC
Hi; the same Issue with Qubes 4.0 + Kali + Burp 1.7.37. Can I somehow download Burp 1.7.28 if it is reported to work ok?

Simon Aug 21, 2018 03:44PM UTC
So I have downloaded Linux installer v1.7.28 and can confirm that the drop-down menus work fine on Debian 8 AppVM under Qubes 4.0

Liam Tai-Hogan Aug 22, 2018 07:51AM UTC Support Center agent

Thanks for the update Simon.

Norman H Aug 24, 2018 07:05PM UTC
Also effects Burp 2.0 Beta.

de Nov 26, 2018 08:21PM UTC
Hi, this specific problem still affects v2.0.12beta on Debian 9 under Qubes 4.0. Any updates or, at least, ideas?

Adrian Nov 28, 2018 10:45AM UTC
Maybe it will help that in the intruder module a similarly functioning filtering module visible after the launch of the attack works correctly.

null Dec 01, 2018 02:34PM UTC
This still persists to be an issue for me as well, and it it currently keeping me from using QubesOS to bolster my personal security regarding client data. The QubesOS team seem unwilling to fix this as they believe it is not their issue. It would be greatly appreciated if this could be resolved.

nil0x42 Dec 03, 2018 12:09PM UTC
I have exactly the same problem, using Qubes OS 4.0 & BurpSuite v1.7.36

Paul Johnston Dec 04, 2018 11:29AM UTC Support Center agent

We’ve believe we’ve identified the change between 1.7.28 and 1.7.29 that introduced this behavior. We’re going to revert this which hopefully will resolve these issues.

nicolas Dec 21, 2018 07:48PM UTC

Is there any update on this?


Paul Johnston Dec 28, 2018 12:18PM UTC Support Center agent

The change will be in the next beta release. We’ll notify you when this is made public.

Post Your public answer

Your name
Your email address