Burp Suite User Forum

Create new post

Automatic Detection of Open Redirection Vulnerability in Portswiggers related Lab

Nico | Last updated: Jan 21, 2021 02:33PM UTC

Hi, why do Burp Professionals's automated scans not detect the open redirection vulnerability in the related "Lab: DOM-based open redirection" (https://portswigger.net/web-security/dom-based/open-redirection/lab-dom-open-redirection). I launched several active scans with no result. Thanks in advance.

Uthman, PortSwigger Agent | Last updated: Jan 22, 2021 02:20PM UTC

Hi Nico, Thanks for reporting this. Please review the feedback below from our research team: The reason our dynamic analysis doesn't find this is because the URL parameter is not reflected anywhere on the page so it cannot see the parameter or inject it. It is very difficult for a scanner to find this sort of vulnerability without any reflection of the input. The location sink is being set when clicking the link and flag it for manual inspection later but automating the discovery of this unknown parameter would be more difficult. We have raised an internal ticket to improve this.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.