Mastering Burp Suite

@mastering-burp.agarri.fr

Tips and tricks for Burp Suite Pro 🛠️ Not affiliated with @portswigger.net ©️ Managed by @agarri.fr 🇫🇷 Additional free resources 🎁 http://hackademy.agarri.fr/freebies

As you may know, I've been giving Burp Suite Pro trainings for the last 10 years And this year, I'll give a single public on-site Burp Suite Pro training session, and it will be in RomHack 🇮🇹 (registration link in replies)

Since EA 2026.2, there's a a search bar in Proxy History and it doesn't work exactly like the usual display filter. Let me explain... - the filter searches in requests, responses and notes - the search bar looks for the keyword in the table of entries itself (including custom and/or hidden columns)

If you're confused by the amount of resources stored in the JAR, here's a hint 🔎 Check out "resources/Scanner/jwt_secrets.txt". It contains over 100k passwords used by the passive scanner to decrypt JWT tokens 🗝️ And it works: that's how @evilpacket.net scored a $1500 bug affecting Cursor 💰

Adam Baldwin@evilpacket.net · last yr.

The finding was for "JWT weak HMAC secret" and it said the secret was literal "secret" A range of emotions pushed me in various directions at once. What? no.!? yes!!!!!!! let's verify...

Hackvertor v2.1.24 has a major bug where it doesn't update the content-length. Sorry about that. I've fixed it in v2.1.25. I'll try and get it updated on the BApp store ASAP. Gutted I missed this, sorry I'll try to do better in future.