You can test web applications and mobile apps using an iOS device. To do this, you need to do the following: Configure your Burp Proxy listener to accept connections on all network interfaces. Connect ...
The BApp Store contains community-created extensions that you can install directly from Extensions > BApp Store in Burp with a single click. We review all extensions submitted to the BApp Store, but ...
Target: The host, path, endpoint, or attached Burp resource to investigate. Question: The security behavior you want Burp AT to test for. Context: Relevant facts, such as intended application behavior ...
This is a quick reference guide to troubleshooting the most common Burp Scanner error messages. You can use Ctrl/Cmd + F to search for the error you've encountered to ...
Burp Collaborator provides custom implementations of various network services on a single server. The server listens for requests that are induced by Collaborator payloads. The server has the ...
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To ...
Webmail has been around for decades and it's always had to solve a very difficult problem of taking untrusted HTML and displaying it to the user in a safe way. This is made even more challenging by ...
This release fixes an issue where Burp AT could incorrectly display a license error when it was unable to refresh your session.
In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Powered Desync ...
This week, we launched Burp AT in public beta for Burp Suite Professional users. Next week at Black Hat, PortSwigger Research will reveal more of the work that helped shape our direction. Burp AT is ...
Logic Mapper is a Burp Suite extension that helps security testers visualize and document complex business logic flows during penetration testing. HTTP requests are represented as nodes on an ...
Burp AT brings agentic AI to human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skills. You decide how much work agents take on. Burp enforces the boundaries ...