The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Automatic Tools

George | Last updated: Feb 10, 2023 09:28AM UTC

Can Burp Suite's vulnerability scanner and/or intruder cause a disruption of service?

Ben, PortSwigger Agent | Last updated: Feb 10, 2023 04:35PM UTC

Hi George, Yes, this is certainly possible. Burp will send a large number of requests during a scan and this can have an impact on performance or simply overload the server causing denial of service issues. The other consideration would be if you are running a scan that includes auditing - the payloads being sent can potentially have a negative or unforeseen impact on the target application (if, for example, you consider Burp sending payloads to test for SQL Injection vulnerabilities then, if the application is vulnerable, the payloads might alter the underlying data causing issues to other users). It is a similar situation with Intruder - although you do have greater control over how many requests you are sending (based on the contents of your payload lists) and what the requests will look like (based on the base request that you are using and where you are configuring your payloads to be placed). Generally speaking, we would always recommend that you scan non-production sites in order to reduce the chance of unforeseen issues occuring.

George | Last updated: Feb 11, 2023 07:54AM UTC