Feature Requests

Post a feature request

  • Extend SQL recognition to responses

    The Active scanner in Burp already identifies SQL statements within queries as potential SQL injection vulnerabilities. However, some applications log the executed SQL statements in the HTML output as comments or in an HTML element hidden with CSS. So just by enabling the already existing algorithm to detect SQL statements within responses as well (not just requests), Burp could detect such inform...

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 09:16AM UTC
  • Double click to open existing project

    It's a commonly implemented UI pattern that when a dialog has a list that you can select elements from and a button to commit to that selection, double clicking an element on the list performs both actions (selecting the item and clicking the button). It'd make opening existing projects (a fairly regular use-case for Burp) a bit easier since the first dialog that appears when opening ...

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 07:51AM UTC
  • how to capture windows based authentication application

    Hi, how to capture windows based authentication application thanks, Anju.

    1 Agent Answer    0 Community Answer
    Oct 19, 2018 05:41AM UTC
  • Specify user/project resolvers

    Hello! I've often found myself in need of switching DNS for an assessment, for various reasons, and I believe that being able to override the system resolvers via Project / User options would be quite handy.

    1 Agent Answer    0 Community Answer
    Oct 13, 2018 08:52AM UTC
  • spider

    When will the professional version of the crawler support front-end frameworks like VUE? In the face of such systems, the reptiles became furnishings.

    1 Agent Answer    0 Community Answer
    Oct 11, 2018 03:45AM UTC
  • Intruder - Payload Processing: Macro - Add prefix/suffix

    On some circustances there is the need to process a dynamic value like anti-csrf token and append this to a parameter. I'm not sure this could be helpful to others, anyway should be a great feature.

    2 Agent Answers    0 Community Answer
    Oct 09, 2018 10:09AM UTC
  • additional decoder compression options

    It would be really useful if decoder had options to deal with deflate and brotli as well as gzip ...

    1 Agent Answer    1 Community Answer
    Oct 02, 2018 12:52PM UTC
  • Shortcut for Action "Do intercept - Response to this request"

    Hello, I use the option "Do intercept - Response to this request" all the time in the Proxy Intercept - tool. Would it be possible to add a shortcut - or even better - add it to the buttons at the top (next to "Forward, Drop, Intercept is on, Action")? That would help me a lot, and save me a ton of time! Or, is there a way I can do this myself by editing the UI so...

    1 Agent Answer    0 Community Answer
    Sep 28, 2018 10:42AM UTC
  • Burp scanner paused for unknown reasons

    In Burp 2.0.07beta, the crawl&scan can sometimes pauses. The message in the Dashboard reads: "Paused do to error: X consecutive audit items have failed." where X is a number (by default the first time it occurs 10). I'm testing a regular Wordpress website that doesn't use cookies at all and has no login mechanism. When the error message in the log is shown, I would li...

    5 Agent Answers    6 Community Answers
    Sep 27, 2018 11:55AM UTC
  • Shared configuration between Pro and Enterprise

    Hi, The Configuration Library is awesome in Beta2, and I can see same pre-defined templates in Enterprise Edition. Would it be possible to cross-promote settings easily? Like show Burp Pro the address to Burp EE, so that it could always take the fresh config, or even change it? In my opinion, people will want to manually improve configuration locally in Burp Pro, which will then be needed to expo...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 01:37PM UTC