Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All
Documentation

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite
Extensibility

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

How Do I?

Make a new post

  • How do I troubleshoot "failed to connect" messages?

    So, I load up Burp Pro, restore defaults (latest versions of burp and JRE), enable the proxy and then in Chrome, with FoxyProxy browse to the site I want to scan/spider. I add said site to scope, and then start spidering. In the alerts tab there will be an increasing number of alerts saying that I failed to connect to the site name, and the same thing happens when I use the scanner. Burp is ...

    1 Agent Answer    0 Community Answer
    Feb 19, 2015 11:53PM UTC
  • MDSEC labs

    Anyone doing the labs from the hacker's handbook? Any possible way someone knows where you can find the answers to the practical labs? Im stucks on a couple of them and would be nice if someone can answer on how it is done.

    0 Community Answer
    Feb 19, 2015 03:36PM UTC
  • get the count (number of pages ) spider crawled

    How can i get the number of pages crawled by the spider

    1 Agent Answer    0 Community Answer
    Feb 19, 2015 09:55AM UTC
  • Transfer License from one laptop to other

    Hi, I have just got a new mac machine in lieu of a windows laptop. I'd my Burp Suite license on the windows machine. How do I transfer it to the Mac? Thanks, Nadeem

    1 Agent Answer    0 Community Answer
    Feb 12, 2015 03:47PM UTC
  • Can I change the domain name or IP address in stored state?

    Hello? I would like to scan actively in domain name B using stored burp state when I scanned passively with domain name A. B would run the same service that A have run. Is this possible? If then, could you let me know how to do it? Thank you.

    1 Agent Answer    0 Community Answer
    Feb 11, 2015 09:57PM UTC
  • How do I manual add a vulnerability

    Using the intruder functionality, i saw the application was vulnerable to a XSS (with a custom payload). Active/Passive Scan doesn't find it. So I have a hit but how can i flag this payload/result with this params as a match within the scanner result (or other place to be able to include this match into the final report) (and of course flag this with a type of XSS vuln and the relevant advi...

    5 Agent Answers    4 Community Answers
    Feb 10, 2015 01:16PM UTC
  • How do I replace the content of a whole file?

    Hi, a web app I am testing is requesting jar files from a web server. I want to replace the jar file the server sends back with a modified version. I can of course intercept the response and manually replace the response content, but this is error prone and takes time. I have certain timing issues that make manually pasting the jar file not an option. So, how do I replace the whole response ...

    2 Agent Answers    1 Community Answer
    Feb 05, 2015 10:18AM UTC
  • Discover content requests with cookies

    Hello, Is it possible to "Discover Content" using valid cookies to test for authenticated pages? I've run several sessions after using the "Discover Content" context menu from a request with a valid cookie, however the cookies do not seem to be used in the brute forcing. Thanks Mark

    1 Agent Answer    1 Community Answer
    Feb 04, 2015 10:53AM UTC
  • java.net.socket Exception when configuring intruder through Burp Extender API

    I am sending multiple HTTP req to intruder with positions marked using sendToIntruder() method in burp Extender API but when I click Launch attack I get java.net.socket in the alerts Tab and no status as 200/400 is coming in the launch attack results box. Can anybody please help in sorting out this

    1 Agent Answer    0 Community Answer
    Feb 03, 2015 10:31AM UTC
  • How to auto load payloads for all intruder attack at one time through Burp Extender API

    I have a payload file with 25 payloads. Can anybody help in sorting out how to auto load payloads through API. IIntruderPayload Generator generates only exetension payload which i need to again manually select from UI. Requirement is to directly load payloads.pay(my custom file) while invoking sendToIntruder menthod from BURP EXTENDER API.

    1 Agent Answer    0 Community Answer
    Feb 03, 2015 08:18AM UTC