This lab's two-factor authentication is vulnerable to brute-forcing. You have already obtained a valid username and password, but do not have access to the user's 2FA ...
But Burp Scanner can. Thanks to its embedded Chromium browser, the web vulnerability scanner at the heart of Burp Suite is able to execute JavaScript in its target application. This allows it to ...
Go to the exploit server and add the following iframe to the body. Remember to add your own lab ID: <iframe src="https://YOUR-LAB-ID.web-security-academy.net/" onload ...
This lab is vulnerable to indirect prompt injection. The application features an AI-powered scanner that has access to sensitive user data, including API keys, while performing site audits. The ...
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
If you need to use an external browser with Burp instead of Burp's preconfigured Chromium browser, perform the following configuration steps. For the vast majority of users, this process is not ...
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
This page answers common questions about how Burp AT and Burp AI keep your testing safe, how you stay in control when using AI features, and how PortSwigger handles the data you send. Both Burp AT and ...
Burp Scanner is an automated dynamic application security testing (DAST) web vulnerability scanner. Designed to replicate the actions and methodologies of a skilled manual tester, Burp Scanner powers ...
Before attempting to install Burp's CA certificate, make sure that you have successfully confirmed that the proxy listener is active and have configured your browser ...
This lab uses a JWT-based mechanism for handling sessions. It uses an extremely weak secret key to both sign and verify tokens. This can be easily brute-forced using a wordlist of common secrets. To ...
CI-driven scans enable you to run Burp Scanner from a Docker container in your CI/CD environment. This is an easy way to integrate Burp Suite DAST with your CI/CD platform. It requires you to set up a ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results