Support Center

Burp Community

See what our users are saying about Burp Suite:

How do I?

New Post View All

Feature Requests

New Post View All

Burp Extensions

New Post View All

Bug Reports

New Post View All

Burp Suite Documentation

Take a look at our Documentation section for full details about every Burp Suite tool, function and configuration option.

Full Documentation Contents Burp Projects
Suite Functions Burp Tools
Options Using Burp Suite

Burp Extender

Burp Extender lets you extend the functionality of Burp Suite in numerous ways.

Extensions can be written in Java, Python or Ruby.

API documentation Writing your first Burp Suite extension
Sample extensions View community discussions about Extensibility

Burp Extensions

Make a new post

  • How do I Set a Token in URL Directory.

    Hi, I want to set a token in URL Directory. And, I use macro. so I want to custmize Macro (on Intruder). Test Site has a Token in URL directory, don't have a url parameter. (Exp. http://xxxxxxxx/test/123456token/) How do I set a Token in URL Directory? I made extender using ISessionHandlingAction. But, I can not custmize macro & intruder...

    1 Agent Answer    0 Community Answer
    Sep 10, 2015 03:00AM UTC
  • Portable Burp Suite: Windows Auto Start Script

    This script will automatically run the latest burp Jar and set java home path for portable installs :) @echo off echo this includes: echo portable java 8 64bit echo python support in burp echo CO2 and Logger++ echo echo cleaning config rem regedit /s INIT_WIPE_CONFIG.reg echo importing config rem regedit /s INIT_BASE_CONFIG.reg echo importing licence file r...

    0 Community Answer
    Sep 04, 2015 07:17PM UTC
  • How to change proxy by an extension when using intruder

    Hello there. I posted a question( ) on forum not long ago, and developer gave me a rather primitive but direct recommendation. Actually, I toke another way to change the proxy on extension( ), like "Traffic rediector example", redirect request HttpService (protocol, host, ...

    2 Agent Answers    2 Community Answers
    Sep 03, 2015 06:34AM UTC
  • Adding GetSiteMap() to Carbonator

    I'm attempting to add to the carbonator extension a method for extracting the sitemap URLs into a text file. The code I have written so far is below, and the output I get is 'array(burp.IHttpRequestResponse)'. I know I need to call the IHttpRequestResponse interface somehow to tap into the array. I import it from burp at the beginning of the code, but when I add that call to the Bur...

    2 Agent Answers    3 Community Answers
    Aug 31, 2015 03:53PM UTC
  • burp hangs while shell command completes

    Hello, I have an extension which calls a shell command that takes a bit to complete. After invoking this from the context menu, burpsuite hangs and resumes after the command completes. I have tried using threading to avoid the hang but have not had any luck. The extension is written in python and I am using Popen and communicate because I need certain tasks to wait until the command completes. A...

    1 Agent Answer    0 Community Answer
    Aug 31, 2015 01:17PM UTC
  • The scanner report size is not consistant for the same web site.

    Hi we have a job (scheduled to run once a day) that invokes BURP (with carbonator extension) through cammand line. this setup is been working for quite a while. when we look at scanner reports we see that some days it is 16MB other days it is 11MB or something else. we want to know why there difference in the repoted issues (or generated report size) for the same website.

    2 Agent Answers    1 Community Answer
    Aug 12, 2015 10:13AM UTC
  • How Does Burp Handle Responses?

    Hi, I hope this is not a duplicate question, but I couldn't find the response to it. I wonder if it is worth checking if the response I'm analyzing for the PDF Metadata Extension is actually a PDF file before reading the response. Does Burp read the whole answer with response = self._requestResponse.getResponse() already? If yes, is the impact on resources high enough that it is...

    1 Agent Answer    0 Community Answer
    Aug 06, 2015 08:24AM UTC
  • How to send a post request?

    I read the document and know that we could use `makeHttpRequest` to send request. I've tried that if I used `PARAM_URL`, it success. I've read this thread before: However, if I change it to `PARAM_BODY`, it failed. My testing web server works well, for example: ``` $curl --data "title=hi&bo...

    1 Agent Answer    1 Community Answer
    Aug 04, 2015 02:31AM UTC
  • Re-writing responses

    I am trying to write my first extension to add a csp header to the response. I have found several articles about adding headers to the requests but none for responses. This if my first try, which does not work. Any pointers to fix this would be appreciated. Thanks! def processHttpMessage(self, toolFlag, messageIsRequest, messageInfo): # determine what tool we would like to pass tho...

    1 Agent Answer    0 Community Answer
    Jul 29, 2015 09:02PM UTC
  • Running automated scans with Carbonator

    We installed Carbonator from within the Burp scanner under the BApp store and ran the following command for as a test: java -jar Xmx2g c:\Users\Desktop\Burpsuite_pro_v1.6..21.jar We received the error message: Error occurred during initialization of VM Could not reserve enough space for 2097152KB object heap. The Burp scanner is running a VM workstation with 4GB of mem...

    3 Agent Answers    2 Community Answers
    Jul 29, 2015 02:19PM UTC