Burp Suite User Forum

Create new post

About out-of-band resource load(HTTP)

Koki | Last updated: Mar 13, 2020 11:06AM UTC

Burp Scanner scans may detect "out-of-band resource load (HTTP)". In some cases, a modified Host header or GET request URI parameter may be detected to the Burp collaborator host name, but this is a natural behavior, not an out-of-band resource load, because it communicates directly with the Burp collaborator rather than with the server being scanned from the HTTP protocol behavior. In this case, is it a false detection?

Hannah, PortSwigger Agent | Last updated: Mar 13, 2020 11:41AM UTC

Unfortunately, we can't provide specific assistance with dissecting/explaining scan reports. You may find the following links helpful: - https://portswigger.net/support/the-burp-methodology - https://portswigger.net/support/burp-testing-methodologies - https://portswigger.net/kb/issues

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.