Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility
Name is required.
Email address is required.
Invalid email address
Answer is required.
Exceeding max length of 5KB

Server down check

Andrej Simko Mar 20, 2017 01:18PM UTC

It would be very good to have some sort of keep-alive functionality to ping server whether it is still up, and depending on the pre-set response by user (e.g. custom error message), it would pause Active scanning until the ping is a success, or user starts it again after making sure the environment is working.
On a "volatile" environment, the Active scanner scans until it is finished, ignoring the state of the server (if some specific error page is set to all requests).
I know that as a part of session management session checking can be done, I'm not aware of a possibility to stop/pause active scanner in case of server-side issues (ideally a user pre-defined).

Dafydd Stuttard Mar 21, 2017 04:04PM UTC Support Center agent

Thanks for this suggestion. We’re planning to provide more capabilities in terms of fully automated crawl-and-scan, and as part of this we will consider ways that we can suspend / throttle the scan in situations where the target application is volatile.

Andrej Simko Apr 25, 2017 08:03AM UTC
Thank you, that's very helpful to know.
In the mean time - is there some API or way to create Extender, which would have the power to pause the Active scan? If not, could something be added in future to be able to control active scanner state via extenders?
Many thanks:)

Dafydd Stuttard Apr 25, 2017 10:25AM UTC Support Center agent

There isn’t currently an API to pause/unpause the Scanner, sorry. We are planning a general revamp of the API and we will look into providing this.

In the meantime, a nasty hack to implement your own pause function would be to use an IHttpListener to hook all requests made by the Scanner, and wait each thread on your own lock object when you want the Scanner to be paused.

Post Your public answer

Your name
Your email address