If you need to use an external browser with Burp instead of Burp's preconfigured Chromium browser, perform the following configuration steps. For the vast majority of users, this process is not ...
To help you decide which deployment method is right for you, you can read a summary of the benefits for each below. Standard Suitable for physical or virtual Windows or Linux machines, including cloud ...
JSON web tokens (JWTs) are a standard format for sending cryptographically signed JSON data between systems. They're commonly used in authentication, session management, and access control mechanisms.
Macros are made up of requests taken from the Proxy history. The first step in adding a macro is to select these requests. To do so: The macro editor displays an editable list of items in the macro.
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
BChecks are custom scan checks that you can create and import. Burp Scanner runs these checks in addition to its built-in scanning routine, helping you to target your scans and make your testing ...
A message editor which contains the WebSocket message to be sent. You can use the message editor functions to analyze and edit the message. The WebSocket connection via which the message is sent. This ...
Reflected input is when data is copied from a request and echoed into the application's immediate response. This is a prerequisite for a range of vulnerabilities, including reflected cross-site ...
You can configure an Android device to proxy HTTP traffic through Burp Suite. This enables you to test Android apps just like ordinary websites. The process for doing ...
Blind cross-site scripting (XSS) is a type of stored XSS in which the data exit point is not accessible to the attacker, for example due to a lack of privileges. To test for blind XSS vulnerabilities, ...
Burp Suite DAST supports SAML-based single sign-on (SSO). This allows users to log in with their existing credentials. You can also integrate SCIM in combination with ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results