Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Bug Reports

Report a bug

  • CONNECT request for plaintext resource fails

    Hi, While testing Metasploit modules during module development, I will often try to pass the HTTP requests Metasploit is making through burp. However, when Metasploit is interacting with a plaintext resource (no SSL), then proxying through burp doesn't work. Only proxying data through burpsuite to an SSL-enable port will allow me to successfully proxy the data. I have determined that th...

    1 Agent Answer    1 Community Answer
    Feb 28, 2017 04:41PM UTC
  • Burp Scanner doesn't use cookie from session handling rule (makro)

    So because I need some testcases for my new burp plugin I tried scanning the Hackerone bug bounty program of . I found a potential bug in Burp's Makro/Session handling. The Makro is not always using the latest cookie that came back in a Set-Cookie header response. My setup: - Burp pro burpsuite_pro_v1.7.17.jar - Disable all scanner checks in "Ac...

    2 Agent Answers    4 Community Answers
    Feb 24, 2017 10:19AM UTC
  • Burp does not set SNI on the outgoing connection to an SSL enabled web server

    Hi there, We run into the following situation the other day: We were testing an SSL enabled application and kept getting connection resets when accessing it via intercepting Burp and correct connections and interactions when accessing it outside a proxy. Some trial error and troubleshooting later it was identified that the server was expecting an SNI to be set. This was validated by us...

    6 Agent Answers    6 Community Answers
    Feb 23, 2017 12:03PM UTC
  • Burp v1.7.17 Pro appears to be dropping HTTPs requests

    Hi everyone. I am having some issues with Burp Suite v1.7.17 Pro. I can load HTTP sites fine and intercept them with the Burp Proxy, but I am unable to load ANY HTTPs sites, the browser just continues to load waiting. I have installed the Burp CA cert as per the instructions. I have tried in Chrome, Firefox and Curl from the commandline to get this working but no luck. I have reset Burp back...

    7 Agent Answers    8 Community Answers
    Feb 20, 2017 01:40AM UTC
  • Firefox Developer Tools shows 200 instead of 302 when using Burp as a proxy

    Not sure why but for some 302 response if I'm using Burp as a proxy on Firefox from Burp Proxy History or Interception I can see the 302 but on Firefox Developer Tools shows me 200. Removing Burp as a proxy from Firefox I can see the same response as 302 on Firefox Developer Tools as supposed to be. On Chrome also using Burp as a proxy the same response I can see as a 302 on Burp and Chrome...

    2 Agent Answers    1 Community Answer
    Feb 16, 2017 05:47PM UTC
  • Bug in Search Windows using openJDK

    Hello dear portswigger team, I have an issue using the Engagement Tools -> Search options. Some times after entering the search word a suggestion window will be created as separate jwindow objects (grey box and white box with digit 1 on the screenshot) and will not be killed after the search windows is closed. That means that these additional windows are still open and running after closing ...

    2 Agent Answers    0 Community Answer
    Feb 16, 2017 12:18AM UTC
  • Burp cant handle same-name cookies set to different paths

    Just chiming in to add another vote for fixing cookie jar handling for cookies with the same name but differing paths. In my case, two different sessionId cookies at root (/) and one at a subdirectory (/service/). Both are necessary for the call. Repeater seems to be adding the first one it encounters in the cookie jar.

    2 Agent Answers    1 Community Answer
    Feb 03, 2017 04:18AM UTC
  • 1.7.17

    This bug just started this morning with 1.7.17..... Temporary project -> load from configuration file-> Start Burp Loads 2 tabs for every extension.

    2 Agent Answers    3 Community Answers
    Feb 02, 2017 04:04PM UTC
  • V1.7.17 and v1.7.16 Issues in Target Tab

    When you run active scan and look at the scan queue, 2 issues found and I come back to the target tab and click on the target and don't see any issues listed in the issues box. In the previous versions this wasn't a problem. A bug probably? Thanks! Iswarya

    1 Agent Answer    0 Community Answer
    Feb 01, 2017 08:09PM UTC
  • Restoring a saved state

    Hey, I was trying to restore a saved state and I keep recieving the same message. The state was stored in 1.7.14 and restored in 1.7.16 burp.f6c at burp.g1g.a(Unknown Source) at burp.g1g.a(Unknown Source) at burp.une.a(Unknown Source) at burp.l4f.g(Unknown Source) at burp.uxc.a(Unknown Source) at burp.a3b.a(Unknown Source) at burp.a3b.a(Unknown Source) at burp.z2b.a(Unknown...

    1 Agent Answer    0 Community Answer
    Feb 01, 2017 04:21AM UTC