The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Add tests for SQL injection with Tabs rather than Spaces?

Adrian | Last updated: Mar 06, 2015 04:50AM UTC

I was working through the Pentester Lab: Web For Pentester (https://www.vulnhub.com/entry/pentester-lab-web-for-pentester,71/) SQL injections, and the Example 2 injection rejects all inputs with spaces in them. Using TAB characters (%09) instead of spaces works, but running the page through Burp Suite Pro's Active Scanner doesn't pick up on the vulnerability. Are there any plans to implement tests for this type of injection, or is there a way to configure Burp so it will detect it?

PortSwigger Agent | Last updated: Mar 09, 2015 04:15PM UTC