The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

ASP.NET ValidateRequest bypass + tuning

vpb | Last updated: Jun 16, 2015 07:19AM UTC

According to my experience Burp Suite doesn't check for this type of ValidateRequest filter bypass: http://www.jardinesoftware.net/2011/07/17/bypassing-validaterequest/ Would it be possible to add this to the Persistens XSS checks? (Sorry if I missed something) On a related note: Since ValidateRequest throws an exception when encountering typical XSS patterns many apps terminate the users session during scanner runs (if XSS checks are enabled). Would it be possible to fine-tune these checks so that they can detect if ValidateRequest filter is present?

PortSwigger Agent | Last updated: Jul 08, 2015 08:02AM UTC