The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

burp active scan

hong | Last updated: Jan 13, 2016 03:48PM UTC

Hi, I am testing a web page (a form) that allows you to make the changes for several fields. The form has several parameters in POST request (name and value pair in the body). If you do not make any changes, and hit submit, it will come back "no change made" page. If you do make change, it will come back with "confirmation page". I did two tests (1) made no change in request, and sent this POST request to the active scan, "active scan" reported 5 issues. (2) made a change in the request, and sent this POST request to active scan, "active scan" reported 22 issues. Is this an expected behavior for "active scan"? I selected almost everything in "attack insertion points", such as "body parameters, head parameters ...". I thought active scan will modify these (name, value) pair and send additional requests for probing the vulnerabilities. I wanted to design my test so that it can give me the maximum issues in the page. Thanks

PortSwigger Agent | Last updated: Jan 14, 2016 09:54AM UTC