The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Active scanning on SPAs

GAYATRI | Last updated: Jul 13, 2023 04:58AM UTC

I am trying to configure active scans on single page applications, and it looks like Burp Suite is unable to run scans thoroughly on such applications. I did try to manually navigate the entire application and submit forms, but the scanners are not able to pick up on the input fields and test for vulnerabilities. Could you let me know if there is a specific configuration that can be made on any of these tools so that the scans are better?

Ben, PortSwigger Agent | Last updated: Jul 13, 2023 12:29PM UTC

Hi Gayatri, If you perform a full crawl and audit scan against your target site (rather than an audit against existing, captured traffic) does this improve how Burp performs against this site?

GAYATRI | Last updated: Jul 14, 2023 05:25AM UTC

Yes, I have tried that, and followed this approach as well https://portswigger.net/burp/documentation/scanner/scanning-spas But it does not look like there is a noticeable change in the crawl/audit quality.

Ben, PortSwigger Agent | Last updated: Jul 14, 2023 10:28AM UTC