When testing web applications, you may encounter challenges relating to session handling and application state. For example: The application may terminate the testing session, either defensively or ...
Due to misconfiguration, some websites support additional HTTP methods that may be useful to an attacker in a number of ways. These include: Enabling you to perform destructive actions like modifying ...
In this tutorial, you'll use Burp Sequencer to analyze the quality of randomness in an application's session tokens. Burp Sequencer may have unexpected results in some applications. Until you are ...
This release adds the option to download issues as a CSV file from the Issues tab. For more information, see Managing issues in Burp Suite DAST. It also includes security fixes.
I'm sure you'll agree that it's pretty shocking, and it works in every browser. It's also a pretty nice way to bypass a WAF. Let's continue the journey. If localName returns a lowercase version of the ...
This release adds customisable title bar actions, multiple evidence items for manually created issues, and evidence highlighting for issues raised by Burp AT. It also includes bug fixes and a Java ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results