The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Additional Scanner Checks Extension

Felix | Last updated: Nov 28, 2014 12:05PM UTC

What is the context in which the Additional Scanner Checks extension decides whether or not a header needs the following properties. strict-transport-security x-content-type-options: no sniff X-XSS-protection Some sites I scan will come back with these findings and some will not. I have not noticed any distinguishable pattern of the sites that come back with these findings. (i.e) logon pages, authenticated pages, home pages, etc. Felix

Liam, PortSwigger Agent | Last updated: Nov 28, 2014 12:06PM UTC