Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All
Documentation

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite
Extensibility

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Feature Requests

Post a feature request

  • No Raw in Response when using Repeater

    I copied my proxy intercept and pasted it in Repeater tab’s Raw. Then click GO (filled host&port), nothing is appeared in Response window. How can i do for see the response raw? (I’m doing webgoat missing function level access control by exercise, and changed proxy-options-proxy listeners interface’s port number from 8080 to 8081 cause it’s unable to click running. My internet proxy option ...

    1 Agent Answer    0 Community Answer
    Oct 27, 2018 06:04PM UTC
  • Dark theme

    Hi! Hackers love to hack by night. And our eyes are so fragile... To be short: I can't wait testing 2beta10 and its new dark theme :-D https://twitter.com/Burp_Suite/status/1055436883805827073 Looking forward!!

    1 Agent Answer    0 Community Answer
    Oct 26, 2018 11:15AM UTC
  • Search among extensions

    Hi! the BApp Store currently includes nearly 200 extensions. When having a specific need, I systematically go the Web version (https://portswigger.net/bappstore) and Ctrl+F the page. That requires Internet access, breaks my testing workflow and doesn't work if the searched criteria only appears in the extended desc. I solved that with a local copy of the BApp Store that I can easily grep. ...

    1 Agent Answer    0 Community Answer
    Oct 26, 2018 11:12AM UTC
  • Side-by-side View

    Hi! Currently, displaying a request+response pair side-by-side is only possible in Repeater ("Repeater -> View -> Left/right split" from the menu bar) or via extensions like Flow or Logger++. I use this layout a lot and I'd like to have it in other areas of Burp Suite, like Target / Site Map, Proxy / History, Intruder results, ...

    1 Agent Answer    0 Community Answer
    Oct 26, 2018 11:03AM UTC
  • Site map - Filter by Tools

    In the Site Map tree, I can see many payloads (in folder and file names) which were used by Active scanner (alone, or by some extension during the Active Scan). Such payloads are: %00grqjw%22a%3d%22b%22sc35f %00prompt(1) ..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini%00index This results from having "URL path filenames" and "UR...

    1 Agent Answer    0 Community Answer
    Oct 25, 2018 08:52AM UTC
  • Extend SQL recognition to responses

    The Active scanner in Burp already identifies SQL statements within queries as potential SQL injection vulnerabilities. However, some applications log the executed SQL statements in the HTML output as comments or in an HTML element hidden with CSS. So just by enabling the already existing algorithm to detect SQL statements within responses as well (not just requests), Burp could detect such inform...

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 09:16AM UTC
  • Double click to open existing project

    It's a commonly implemented UI pattern that when a dialog has a list that you can select elements from and a button to commit to that selection, double clicking an element on the list performs both actions (selecting the item and clicking the button). It'd make opening existing projects (a fairly regular use-case for Burp) a bit easier since the first dialog that appears when opening ...

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 07:51AM UTC
  • how to capture windows based authentication application

    Hi, how to capture windows based authentication application thanks, Anju.

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 05:41AM UTC
  • Specify user/project resolvers

    Hello! I've often found myself in need of switching DNS for an assessment, for various reasons, and I believe that being able to override the system resolvers via Project / User options would be quite handy.

    1 Agent Answer    0 Community Answer
    Oct 13, 2018 08:52AM UTC
  • spider

    When will the professional version of the crawler support front-end frameworks like VUE? In the face of such systems, the reptiles became furnishings.

    1 Agent Answer    0 Community Answer
    Oct 11, 2018 03:45AM UTC