I'm sure you'll agree that it's pretty shocking, and it works in every browser. It's also a pretty nice way to bypass a WAF. Let's continue the journey. If localName returns a lowercase version of the ...
Webmail has been around for decades and it's always had to solve a very difficult problem of taking untrusted HTML and displaying it to the user in a safe way. This is made even more challenging by ...
In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Powered Desync ...
Throughout May 2026 we ran Extensibility Month on the PortSwigger Discord server - a full month of talks, workshops, community sessions, and the Burp Extension Awards, decided by community vote. The ...
This release updates the bundled Java runtime to Java 26. It also includes improvements to Burp Scanner and a range of bug fixes.
This release introduces a combined installer for Burp Suite Professional and Community Edition, greater extension control over HTTP traffic, Markdown support in Notes, and collection-level notes in ...
Today, we are delighted to launch our official Burp Ambassador Program: a community initiative to collaborate more closely with experienced Burp users, and support the great work they’re already doing ...
Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year ...
Postman Collection Importer converts Postman collections and environments into Repeater tabs and Sitemap entries. The extension supports variable resolution, authentication methods, and multiple ...
This release adds a command palette for faster keyboard navigation, improved memory controls, and enhanced OAST support in custom scan checks. We've added a Command palette to help you quickly find ...
WebSocket Turbo Intruder is a Burp Suite extension for fuzzing WebSocket messages with custom Python code. It extends the Burp Suite engine so it can exploit the WebSocket protocol specific ...
Sometimes people think they've found HTTP request smuggling, when they're actually just observing HTTP keep-alive or pipelining. This is usually a false positive, but sometimes there's actually a real ...