Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All
Documentation

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite
Extensibility

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Feature Requests

Post a feature request

  • Proxy tab Http history - display both request and response of the selected message

    Hello, It would be great, if by default both request and response are displayed in the Proxy Http History tab. In the current implementation, you have to choose request or response in the message view. Thank you Best regards Frantisek Uhrecky

    0 Community Answer
    Sep 27, 2016 08:37PM UTC
  • Use Collaborator in manual testing

    I want to use collaborator while manual site testing. I think my case is very typical - I found some not typical SSRF vulnerability (which can't detect active scan) and want to check it. Now I must use my own NS server, because can't check it with Burp Collaborator. What I want to see: - Send request to Repeater - Place collaborator payload in the request - Send it and get aler...

    1 Agent Answer    0 Community Answer
    Sep 27, 2016 11:46AM UTC
  • Extend API Functionality (Stream Proxy + WebSocket)

    Hi, I want to write new extensions for BurpSuite, For one of them i need To Set Stream Proxy (PyMultitor), For the other one i need to see WebSocket Raw Sockets To Show And Fuzz Every Parameter.

    1 Agent Answer    0 Community Answer
    Sep 23, 2016 09:42PM UTC
  • partial JSON config files

    Currently when starting a new burp project and loading it with a config file, you have to have every option filled in the JSON, otherwise it'll leave that field as blank in the new project. I'd really like it if you could just have your JSON config file contain what you wanted different ( like targets excluded from scope, regex to exclude on scanners, private burp collab server, etc),...

    2 Agent Answers    0 Community Answer
    Sep 21, 2016 01:47PM UTC
  • Custom response grep/extract/post-processing in Burp Intruder?

    Burp Intruder supports response grep by regexp, and shows every match in a separate column in result table. It would be helpful to create a custom response processor, written in any language (Python preferred), to generate an extra column value for each request. For example, for each request I need: 1. Access to body 2. Count "words" 3. Return integer value and display it in extr...

    1 Agent Answer    0 Community Answer
    Sep 20, 2016 03:39PM UTC
  • .NET plugins support

    Would be great giving .net support to develop burpsuite plugins

    1 Agent Answer    0 Community Answer
    Sep 16, 2016 12:25PM UTC
  • Burp Infiltrator destroys Spring Boot application

    Hi, when using Burp Infiltrator on a JAR file, which has been created as a Spring Boot application, then the application is not able to start, especially when embedded server is Jetty. Would be great if Burp Infiltrator would be able to support such JAR files! Thanks and Regards Denis

    1 Agent Answer    0 Community Answer
    Sep 16, 2016 07:06AM UTC
  • Proxy Intercept window: show proxy listener that received the request

    Sometimes I configure Burp with multiple proxy listeners going through the same instance. The Proxy History does a great job at being able to separate the traffic with both a dedicated column for the target port and also a filter for the same. In this scenario with proxy interception enabled, sometimes it happens that requests hit more than one of the proxies at the same time, and I want to per...

    1 Agent Answer    0 Community Answer
    Sep 13, 2016 05:04PM UTC
  • Add more functionality in "Discover Content"

    Hello , you could add more functionality in "Discover Content" like the functionality of a custom list and also an option to stop the specific task(example stop directory brute force in the selected subfolder...)

    1 Agent Answer    0 Community Answer
    Sep 06, 2016 11:56AM UTC
  • Burp Sequencer feature - Define payload type

    Hello, I would like to see a choice for the Sequencer payload type. Meaning if I want to run statistical tests and entropy for 20000 tokens ,I would like to be able to define exactly what type these tokens can be . An example would be 20000 tokens of unsigned integers from range 0-100. A good entropy would be about 6 bits , but currently the sequencer claims that this is very poor entropy . ...

    0 Community Answer
    Sep 03, 2016 05:58PM UTC