Burp Suite User Forum

Create new post

maybe a problem with the lab : Reflected XSS protected by very strict CSP, with dangling markup attack

I can solve the lab when I play the role of the victim but when I send payload to the victim I don't get the CSRF token

Last updated: Apr 25, 2024 09:52PM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Slow lab response times

The lab 'Lab: Reflected XSS with event handlers and href attributes blocked' (https://portswigger.net/web-security/cross-site-scripting/contexts/lab-event-handlers-and-href-attributes-blocked) seems to be responding very...

Last updated: Apr 25, 2024 05:57PM UTC | 4 Agent replies | 7 Community replies | Bug Reports

Availability- The website is too slow now a days

Dear Portswigger Team, I hope this letter finds you well. I am writing to express my frustration and disappointment regarding the current performance issues with the Portswigger website and Portswigger Academy labs. As...

Last updated: Apr 25, 2024 04:41PM UTC | 9 Agent replies | 20 Community replies | Bug Reports

The "Parameters" tab does not appear in "API details"

Hello. Please help me with the following question. When I try to run an API scan (New scan > API scan) I encounter the problem that there is no tab "Parameters" in "API details" (New scan > API scan > API details >...

Last updated: Apr 25, 2024 11:16AM UTC | 0 Agent replies | 0 Community replies | Bug Reports

Some of the CORS labs don't work anymore on firefox and chrome

Some of the CORS labs don't work anymore since a new update on firefox and chrome due to new security put into place on third party cookies called 'Partitioned' attribute. While it is still possible to solve the lab by...

Last updated: Apr 25, 2024 09:52AM UTC | 2 Agent replies | 0 Community replies | Bug Reports

Installing Burp Suite on Kali Linux Virtual Machine in a MAC Computer M2 processor

Hi, I am trying to install Burp Suite on Virtual Machine running Kali Linux. My computer is a MAC with M2 processor. I include the following command on my terminal: sudo apt-get install...

Last updated: Apr 24, 2024 05:31PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

BSCP exam bug

Hello! I had an BSCP exam finished few minutes ago and I failed it. I solved first app in one hour and other time I spent on second app, but can't go even through the first step, I think it might be some issue on the...

Last updated: Apr 24, 2024 10:24AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Lab freezes when deploying xss

The first two xss labs (I have not tried the others) crashes when xss payloads are sent. For example in the first lab i type the xss payload into the search box and click the search button. And Then, the web site starts load...

Last updated: Apr 24, 2024 07:24AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

I cannot access any of the labs, I keep getting the "Bad Request" error message

Tried Brup's built in browser, Firefox, resetting the learning path.

Last updated: Apr 24, 2024 06:57AM UTC | 3 Agent replies | 2 Community replies | Bug Reports

Unable to check for updates due to network error, in return resulting to license activation reached its limit

After installing burp and loading the license and tried to do update suddenly the burpsuite pro has an error saying "unable to check for updates due to network error. Please check your network configuration and try again". I...

Last updated: Apr 23, 2024 10:11AM UTC | 2 Agent replies | 2 Community replies | Bug Reports

IScannerInsertionPoint.getPayloadOffsets() causes scan failures when null is returned

Hi, I'm building an extension for scanning custom serialized data and encountered a bug in IScannerInsertionPoint.getPayloadOffsets() From the getPayloadOffsets() JavaDoc: """ Returns: An int[2] array containing the...

Last updated: Apr 23, 2024 09:59AM UTC | 1 Agent replies | 2 Community replies | Bug Reports

httpResponseReceived.body() returns everything that follows a HTTP/1.1 100 Continue header as the body

In a recent Burp update, httpResponseReceived.body() now breaks if the response starts with HTTP/1.1 100 Continue. The following is an example: HTTP/1.1 100 Continue HTTP/1.1 200 Access-Control-Allow-Origin:...

Last updated: Apr 22, 2024 12:22PM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Lab: Web cache poisoning via an unkeyed query string

Hi, I have tried repeatedly to do this lab with no results. My problem is that whatever request I send the X-Cache always responds to me Miss. Either from the opriginal request to the home, adding a cachebuster payload,...

Last updated: Apr 22, 2024 09:58AM UTC | 2 Agent replies | 3 Community replies | Bug Reports

Labs keep crashing

Hi, I am currently doing the API labs. Every time i try to do a lab in the academy, the servers keep crashing and i have to wait approx 10 minutes for them to come back online and start working again..Just for them to...

Last updated: Apr 22, 2024 08:04AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Insane Lag

Recently the labs take forever to load, and they go down in like 5 min and its imposible to solve a lab.

Last updated: Apr 22, 2024 07:39AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

burpsuite_community_windows-x64_v2024_2_1_5 does not match its checksum

The community edition burpsuite_community_windows-x64_v2024_2_1_5 does not match its checksum for either SHA 256 or MD5. The file has been downloaded several times, and the result is always the same. "SHA256 ...

Last updated: Apr 20, 2024 09:22PM UTC | 0 Agent replies | 1 Community replies | Bug Reports

Big space after words

I'm using Burpsuite (newest stable) in 2K monitor in ParrotOS, and there seems to be a rendering error only in Request/Response field where I see space cursor far behind character position where I typed. There seems to be a...

Last updated: Apr 19, 2024 11:21AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

'Credit Card numbers disclosed' finding false positive

Hi there, Using Burp 2024.2.1.5. As part of passive scanning a 'Credit Card numbers disclosed' finding was reported: Issue detail: The following credit card number was disclosed in the...

Last updated: Apr 19, 2024 07:53AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: CSRF where token is tied to non-session cookie solution not working due

Hi, i have an issue getting the solution to the lab working. Whenever i try to set the value of the csrf token with /?search=test%0d%0aSet-Cookie:%20csrfKey=8TIB6mcBo8vOoLZ1nSPocJae9QLOWMAw%3b%20SameSite=None the...

Last updated: Apr 18, 2024 11:38PM UTC | 2 Agent replies | 2 Community replies | Bug Reports

Double cookie header created by session handling rule

If you create a session handling rule to either add or update a cookie value for requests in some scope, it does not work as expected. The setup is: * a enabled session handling rule; * with any given scope; * a "set a...

Last updated: Apr 18, 2024 03:05PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Page 1 of 142

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image