Burp Suite User Forum

Login to post

Burp report

Bappe | Last updated: Dec 14, 2019 02:29PM UTC

Why report is different for following scenario: a. Scan without any pause or interrupt. b. Scan with few pause or burp restart

Mike, PortSwigger Agent | Last updated: Dec 16, 2019 10:47AM UTC

Hi, Would you be able to provide us with an example?

Burp User | Last updated: Dec 17, 2019 04:24AM UTC

Why report is different for following scenario: a. Scan without any pause or interrupt. b. Scan with few pause or burp restart example: for option "a" the scan found 10 issues and for option "b" the scan found 9 issues on the same target and same scan configuration.

Liam, PortSwigger Agent | Last updated: Dec 17, 2019 10:40AM UTC

It's not clear why this difference in results might have occurred. How many times have you run this test? Are you able to reproduce this consistently? Which version of Burp are you using? Are you able to manually verify the results of the scan? The actual impact and validity of any issue will always depend on the nature of the application functionality and the business context in which it appears. Hence, issues should always be manually reviewed based on the tester's knowledge of the application.

You need to Log in to post a reply. Or register here, for free.