Feature Requests

Post a feature request

  • Burp REST API - capturing traffic

    Hi, in my experience, launching an active scan on valid dataset from Proxy is the best approach. We have regular releases, triggering test packs for changed functionality which can be routed through Burp Suite. So far, we always opened manually new Proxy listener, captured traffic, closed it, and ran active scan. Would it be possible, to enhance the REST APIs to be able to start listening on c...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 11:04AM UTC
  • Burp Enterprise - blackout periods

    Hi, would it be possible to add a feature in Scheduling GUI for blackout periods? For example, every day, twice a day, during certain hours there are locks on environments for regression testing, during which the environment should not be used. Or, if the scan is of production, and they need to test it only during work hours when there is someone on-call, we want to be able to tweak it as such. ...

    1 Agent Answer    0 Community Answer
    Sep 26, 2018 10:54AM UTC
  • Automating burp scans

    Hello, We are interested in automating scans using Burp Suite. I came across this post/thread discussing the same where it was suggested that this capability would be available in future and currently instead had to use Carbonator - https://support.portswigger.net/customer/portal/questions/11576248-automating-burp-scan Wanted to check if there have been any development on this feature since...

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 10:27PM UTC
  • Highlight data that has been automatically changed by burp

    It would be helpful to visually mark data that has been automatically changed in a request/response by Burp. Occasionally, I'll stumble when some request data has been changed by a session handling rule or req/resp matcher without me noticing it. It would be nice if the data in question is highlighted or colored in the editor window to denote the change.

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 04:12PM UTC
  • Enterprise Edition proxy for scan agents

    Hi, If I understand it correctly, currently, when I add proxy in Burp EE, it's mainly used for sharing feedback with portswigger (correct me if I'm wrong). However, because of various issues with Burp 2 at the moment (running into noscript directive and always being redirected elsewhere; and problems with using current user-agent), the scan of a very big site is finished within a few r...

    1 Agent Answer    0 Community Answer
    Sep 24, 2018 12:16PM UTC
  • Adding certificates to the trust store in order to get Burp updates

    Would it be possible to add something in the user options in Burp to add a certificate to the trust store? In some environments in order to reach the internet you must go through a proxy and sometimes that proxy is configured to do SSL interception which means you need to install the proxy's certificate into the JVM's trust store before you can download Burp updates from the UI.

    1 Agent Answer    0 Community Answer
    Sep 21, 2018 03:07PM UTC
  • Hiding file path from CSRF PoC

    Hello, I have a request for CSRF PoC. When I open a CSRF PoC html on a local disk, the file path of the PoC is showed on a tab in the browser. I would like to hide the pass when I attach a screenshot of the PoC to a document. Currently I add a title element to the PoC manually, like this: <meta><title>CSRF PoC</title></meta> Would it be possible to add the title ...

    1 Agent Answer    0 Community Answer
    Sep 21, 2018 04:06AM UTC
  • comment repeater items

    Dear Team, it would be helpful if I could add comments/remarks to each separate request within a tab in the repeater tool (the same way as items can be commented in the proxy history). Zsolt

    1 Agent Answer    0 Community Answer
    Sep 17, 2018 02:46PM UTC
  • New functionality - More information about responses

    Hi, I was thinking about a new functionality, which I believe may be very helpful during manual testing:) It would be using a library of pre-defined regular expressions and custom messages/colorings. If the response satisfies some regexp, it would be passively shown to the user in {Proxy, Repeater, Intruder}. There are many errors in the environment I work on, and sometimes it can be hard to not...

    1 Agent Answer    1 Community Answer
    Sep 17, 2018 12:57PM UTC
  • Disable notification to upgrade to Burp 2.0

    Can you please add an option to disable notification to upgrade to Burp 2.0? I'm planning on staying in Burp 1.x for now. It gets tedious click close each time I open Burp.

    1 Agent Answer    1 Community Answer
    Sep 14, 2018 04:57PM UTC