# Burp extension released: Send to Dradis

**URL:** <https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383>\
**Category:** Community Edition\
**Created:** [November 4, 2016, 10:32pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383 "2016-11-04T22:32:45Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![etd](https://yyz1.discourse-cdn.com/flex035/user_avatar/discuss.dradis.com/etd/32/5_2.png) [@etd](https://discuss.dradis.com/u/etd)\
**Post date:** [November 4, 2016, 10:32pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/1 "2016-11-04T22:32:45Z")

</div>

We’ve created a Burp extension that adds a context menu to send Issues directly to Dradis from Burp’s Scanner interface.

 ![](https://canada1.discourse-cdn.com/flex035/uploads/dradisframework/original/1X/6472c2d7e3b39654018542e33dca1538e73589ef.png)

Download and instructions:

> **[GitHub - dradis/burp-dradis: Dradis Framework extension for Burp Suite](https://github.com/dradis/burp-dradis)**
>
> Dradis Framework extension for Burp Suite. Contribute to dradis/burp-dradis development by creating an account on GitHub.

If you give it a try, let us know what you think.

-Daniel

---

<div class="post-metadata">

**Author:** ![LanMan](https://avatars.discourse-cdn.com/v4/letter/l/a5b964/32.png) [@LanMan](https://discuss.dradis.com/u/LanMan)\
**Post date:** [November 18, 2016, 5:29pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/2 "2016-11-18T17:29:36Z")

</div>

Where can we find the API token required for the Burp Plugin?

---

<div class="post-metadata">

**Author:** ![etd](https://yyz1.discourse-cdn.com/flex035/user_avatar/discuss.dradis.com/etd/32/5_2.png) [@etd](https://discuss.dradis.com/u/etd)\
**Post date:** [November 18, 2016, 7:46pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/3 "2016-11-18T19:46:35Z")

</div>

Hi @LanMan,

For CE it’s the shared password of the server. For Pro, in your Profile page.

HTH,  
Daniel

---

<div class="post-metadata">

**Author:** ![LanMan](https://avatars.discourse-cdn.com/v4/letter/l/a5b964/32.png) [@LanMan](https://discuss.dradis.com/u/LanMan)\
**Post date:** [November 18, 2016, 9:53pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/4 "2016-11-18T21:53:52Z")

</div>

Thanks, still having a problem. I deployed Dradis on Cloud9 (not sure if that is the issue).  
Here are screenshots:

Burp Config

 ![](https://canada1.discourse-cdn.com/flex035/uploads/dradisframework/original/1X/2106cdad4278778bdb3d5bcf289bea883d5ce49b.png)

---

<div class="post-metadata">

**Author:** ![LanMan](https://avatars.discourse-cdn.com/v4/letter/l/a5b964/32.png) [@LanMan](https://discuss.dradis.com/u/LanMan)\
**Post date:** [November 18, 2016, 9:54pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/5 "2016-11-18T21:54:38Z")

</div>

Message when sending issue  
 ![](https://canada1.discourse-cdn.com/flex035/uploads/dradisframework/original/1X/b4b252d6a1fc75ac1e627401ac8cb7e89adc9a08.png)

---

<div class="post-metadata">

**Author:** ![etd](https://yyz1.discourse-cdn.com/flex035/user_avatar/discuss.dradis.com/etd/32/5_2.png) [@etd](https://discuss.dradis.com/u/etd)\
**Post date:** [November 21, 2016, 2:26pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/6 "2016-11-21T14:26:13Z")

</div>

Hi @LanMan,

Can you confirm the output of:

```
curl -i -u etd:[pass] http://dradis-ce.dev/api/issues

```

For your C9 URL? Unless that is working there is something going on with the connection (SSL cert), domain, port, password, etc.

HTH,  
Daniel

---

<div class="post-metadata">

**Author:** ![LanMan](https://avatars.discourse-cdn.com/v4/letter/l/a5b964/32.png) [@LanMan](https://discuss.dradis.com/u/LanMan)\
**Post date:** [December 29, 2016, 1:39am UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/7 "2016-12-29T01:39:43Z")

</div>

I never followed up on this one, I ended up buying to pro version. If anyone else has the same issue I am sure they will bump this thread.

---

<div class="post-metadata">

**Author:** ![etd](https://yyz1.discourse-cdn.com/flex035/user_avatar/discuss.dradis.com/etd/32/5_2.png) [@etd](https://discuss.dradis.com/u/etd)\
**Post date:** [February 7, 2017, 1:55pm UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/8 "2017-02-07T13:55:08Z")

</div>

It was a long an arduous debug process, it came down to Ruby \> JRuby \> Java not taking the same path to make an HTTP request than Burp does, so we had to rewrite the HTTP-sending part of the extension. You can follow progress here:

[https://github.com/dradis/burp-dradis/pull/1](https://github.com/dradis/burp-dradis/pull/1)

Background info:

> **[Let's Encrypts certificates - Burp Suite User Forum](https://forum.portswigger.net/thread/let-s-encrypts-certificates-edf48629)**
>
> Burp appears to mark certs issued by Let's Encrypt as untrusted. Because of this, some plugins, like the relatively recent Dradis Framework plugin...

> **[jruby SSLSocket error - Burp Suite User Forum](https://forum.portswigger.net/thread/jruby-sslsocket-error-576615798a8d4e)**
>
> I'm currently developing the Dradis Framework Burp extension (https://github.com/dradis/burp-dradis/) and I'm encountering an error when the...

---

<div class="post-metadata">

**Author:** ![etd](https://yyz1.discourse-cdn.com/flex035/user_avatar/discuss.dradis.com/etd/32/5_2.png) [@etd](https://discuss.dradis.com/u/etd)\
**Post date:** [February 14, 2017, 8:00am UTC](https://discuss.dradis.com/t/burp-extension-released-send-to-dradis/383/9 "2017-02-14T08:00:23Z")

</div>

This should be fixed in v0.0.3. It’s not released in Burp’s store yet, but you can give it a try here:

[https://raw.githubusercontent.com/dradis/burp-dradis/master/burp-dradis.rb](https://raw.githubusercontent.com/dradis/burp-dradis/master/burp-dradis.rb)
