Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Burp Extensions

Make a new post

  • Extension does not load when BURP is loaded through Windows Task Scheduler while not logged in

    I'm trying to run BURP with my extension with the Windows's Task Scheduler. When I'm logged in, the Task Scheduler is able to open BURP in headless mode and preload my python extension fine. The issue is when I'm not logged into the Windows. I written an command line output to txt file so I see BURP was successfully opened, but I don't see my see outputs from my extensi...

    3 Agent Answers    2 Community Answers
    Apr 04, 2018 05:59PM UTC
  • BurpSmartBuster Not Working

    Hello, Whenever I try to use BurpSmartBuster it generates errors and does not work properly. It had worked at some point in the past, but that was at least 6 months ago. I am using Burp Suite Pro 1.7.32, on Windows 10. These are the errors I see in the Extender section for BurpSmartBuster: Exception in thread Thread-smartRequest:Traceback (most recent call last): File "C:\Users\&l...

    1 Agent Answer    0 Community Answer
    Mar 25, 2018 06:43PM UTC
  • Design new extension - Problem with buildRequest and URL Encode

    Hi! I'm new to extending Burp and I wanted to add an active scanner plugin for some injections. When I making the requests with a payload with special characters, for example <script>alert(1)</script>, the request encoded my payload with "URL encode". My code is as follows: for(String payload: payloads){ IHttpRequestResponse test = this.callbacks.makeHttpRe...

    6 Agent Answers    6 Community Answers
    Mar 23, 2018 12:11PM UTC
  • burp collaborator

    How to use collaborator and what are settings for to use it? and can any one provide me an example for how it works.

    1 Agent Answer    0 Community Answer
    Mar 22, 2018 05:12PM UTC
  • callbacks.makeHttpRequest encode special characters to url encode

    Hi! When I making the requests with special characters, for example <>, the request is encoded with "URL encode". How could I send the request without encoding anything? My code is as follows: for(String payload: payloads){ IHttpRequestResponse test = this.callbacks.makeHttpRequest(httpService,insertionPoint.buildRequest(helpers.stringToBytes(payload))); } The reque...

    1 Agent Answer    0 Community Answer
    Mar 21, 2018 09:04AM UTC
  • API function to check if URL is in scope?

    I have created a custom extension that takes all requests of a certain domain from the sitemap, does some magic on the insertion points and then adds the requests with custom insertion points to the active scanner. I'm having a problem with ensuring that I only add requests that are in scope. Is there an API function that can be called to check if an URL is in scope?

    1 Agent Answer    0 Community Answer
    Mar 13, 2018 09:55AM UTC
  • How is PHP Object Injection is reported by burp extension "PHP Object Injection Check"?

    While scanning the XVWA (Xtreme Vulnerable Web Application) consisting the vulnerability-PHP Object Injection i.e. Insecure Deserialization, burp extension "PHP Object Injection Check" doesn't report with the same name. As burp insert payload PDO object also means plug-in is working, but vulnerability is not getting reported. If there are any prerequisites for using this plugi...

    1 Agent Answer    0 Community Answer
    Mar 01, 2018 08:38AM UTC
  • How to deploy an extension

    Any guides out there on getting started writing extensions? I've found sample extensions and I can build them with Intellij, but I'm not familiar enough with java to create the jar file. Thanks

    1 Agent Answer    0 Community Answer
    Feb 26, 2018 06:50PM UTC
  • Replicator: Not Able to Edit 'Grep Expression' field

    Hi Burp, I have installed the Replicator extension and can send requests to it. However, when creating a replicator file as a tester, I am not able to edit the 'Grep Expression' field or add/select any expression to it. Do I need to make any changes prior to editing the field? Please note I can run the 'Test' and use other buttons(except Save) at this moment. However, i...

    1 Agent Answer    0 Community Answer
    Feb 15, 2018 08:30AM UTC
  • BURP WS-Security SOAP Webservices security testing

    I see the raw request with junk data for one of the operation in Wsdler. I added the Send to Intruder for the request in wsdler operation and when I navigate to Intruder, I encountered an error.Can you please suggest the way how I can add the keystore to make the encryption and decryption successful and how to verify the security of the web services?

    1 Agent Answer    0 Community Answer
    Jan 24, 2018 07:43PM UTC