This learning path explores authentication vulnerabilities, which have a critical impact on security. You'll learn about common mechanisms and vulnerabilities, and strategies for robust authentication ...
I'm sure you'll agree that it's pretty shocking, and it works in every browser. It's also a pretty nice way to bypass a WAF. Let's continue the journey. If localName returns a lowercase version of the ...
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
Custom actions are scripts that run directly in Burp Repeater to automate tasks and extract information during manual testing. This page includes useful code snippets and building block examples of ...
If you need to use an external browser with Burp instead of Burp's preconfigured Chromium browser, perform the following configuration steps. For the vast majority of users, this process is not ...
This release adds customisable title bar actions, multiple evidence items for manually created issues, and evidence highlighting for issues raised by Burp AT. It also includes bug fixes and a Java ...
Burp Suite contains a wealth of features and capabilities to support manual and automated security testing. Use the links below for more information: Like any security testing software, Burp Suite ...
The process for installing Burp's CA certificate varies depending on which browser you are using. Please select the appropriate link below for detailed information ...
Cross-site scripting (XSS) is a web security vulnerability that enables an attacker to manipulate a vulnerable web site so that it returns malicious JavaScript to users. Attackers can use malicious ...
Many servers now support HTTP/2. This exposes them to potential vulnerabilities that are impossible to test for using tools that only speak HTTP/1. Burp Suite provides unrivaled support for ...
Professional By default, attacks are saved in-memory, so they are lost if you close Burp Suite. However, you can save them to your project file. Select Save attack to project file. We recommend that ...
Prototype pollution is a JavaScript vulnerability. It enables an attacker to add arbitrary properties to global object prototypes, which may then be inherited by user-defined objects. This enables ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results