But Burp Scanner can. Thanks to its embedded Chromium browser, the web vulnerability scanner at the heart of Burp Suite is able to execute JavaScript in its target application. This allows it to ...
This lab is vulnerable to indirect prompt injection. The application features an AI-powered scanner that has access to sensitive user data, including API keys, while performing site audits. The ...
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
Burp Scanner is an automated dynamic application security testing (DAST) web vulnerability scanner. Designed to replicate the actions and methodologies of a skilled manual tester, Burp Scanner powers ...
You can set the type of payload that you want to inject into the base request. Burp Intruder provides a range of options for auto-generating different types of ...
CI-driven scans enable you to run Burp Scanner from a Docker container in your CI/CD environment. This is an easy way to integrate Burp Suite DAST with your CI/CD platform. It requires you to set up a ...
When you launch a Burp Intruder attack, the attack runs in a new results window. This contains the attack results, and a clone of the configuration side panel from which the current attack is based.
If you need to use an external browser with Burp instead of Burp's preconfigured Chromium browser, perform the following configuration steps. For the vast majority of users, this process is not ...
This page answers common questions about how Burp AT and Burp AI keep your testing safe, how you stay in control when using AI features, and how PortSwigger handles the data you send. Both Burp AT and ...
This lab is vulnerable to username enumeration and password brute-force attacks. It has an account with a predictable username and password, which can be found in the following wordlists: Log in using ...
This lab is vulnerable to indirect prompt injection. The application features an AI-powered scanner that can be manipulated into exploiting a routing-based SSRF ...