tristanlatr / burpa

Burp Automator - A Burp Suite Automation Tool. It provides a high level CLI and Python interfaces to Burp Suite scanner and can be used to setup Dynamic Application Security Testing (DAST).
GNU General Public License v3.0
190 stars 37 forks source link

Burp Suite v2023.7.2 breaks Burpa #24

Closed mariobrostech closed 1 year ago

mariobrostech commented 1 year ago

Hi,

After updating my Burp Suite JAR file to v2023.7.2, I noticed that none of my scans were returning any reports following the update. I did some testing, and it looks like something has changed in the latest Burp Suite release that breaks Burpa. Every scan that I perform shows the proper logging in the Burp Suite interface itself (with headless mode disabled), but none of these errors reach the Burpa console log.

As a result, each scan ends with the message "No issue could be found for the target http://..." and doesn't output anything to the folder that I have specified the reports to be saved to. I can't tell if this is an issue with Burpa or one of the other APIs that it's using to generate reports. If you could please look into this, I would really appreciate it! Additionally, if you need help reproducing the issue, I'd be happy to assist.

Thanks in advance for your help!

tristanlatr commented 1 year ago

You're right, I'm having the same issue. I think the issue should be reported in but-rest-api repo, it's not related to our processes in burpa.

Thanks fort he report.

tristanlatr commented 1 year ago

Im open for suggestions, @mariobrostech... Have you tried with newer version of Burp Suite ?

tristanlatr commented 1 year ago

I don't see anything in the release notes that could point into dropping support for whatever we're doing here.

tristanlatr commented 1 year ago

Just tested with Burp 2023.10.1.1 and it worked. Tell me if this works on your side as well @mariobrostech