The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp Collaborator WAF triggering/not obeying options

Ciaran | Last updated: Feb 11, 2018 12:52AM UTC

Hey, I am currently using Burp to run an assessment on a website. They use Incapsula as a WAF, which is being triggered very frequently. At first I thought it might be related to spidering too fast, but I modified the spider to go extremely slow which didn't help. I then tried browsing the site without proxying through Burp and everything worked as expected. I tried to disable collaborator in the project misc settings but it is still injecting payloads in several HTTP headers. WAF error. " Error code 15 This request was blocked by the security rules 2018-02-11 00:49:47 UTC Your IP 52.56.127.52 Proxy IP 107.154.76.95 " Any help would be appreciated.

Burp User | Last updated: Feb 11, 2018 01:03AM UTC

I found a temporary solution by unloading the extension in the Extender tab. I had presumed that the collaborator was part of the core engine. Regardless there still seems to be an issue that it does not respect the option set in Project options -> Misc

PortSwigger Agent | Last updated: Feb 12, 2018 10:02AM UTC