Burp Suite User Forum

Create new post

Burp Scanner

Lilia | Last updated: Oct 30, 2022 09:16PM UTC

Hello, I have recently checked the work of Burp scanner on Burp Exam where Insecure Deserialization vulnerability is present exactly, but there is no issue of this vulnerability detected by Burp Scanner. As I know other users had the same results, so it means that unfortunately Scanner is not as efficient as it was before for applications, where Insecure Deserialization vulnerability exists. Please, may you help me with it? Because the proper work of Scanner with Serialized objects is required. Should I request this post with a category of Feature request? Best Regards

Michelle, PortSwigger Agent | Last updated: Oct 31, 2022 08:44AM UTC

Thanks for getting in touch. To help us look into this, can you email support@portswigger.net describing the steps you were taking and what you were expecting Burp Scanner to find, please? Is this something that earlier versions of Burp Scanner have successfully found? Are you using any extensions? Were you working on the practice exam, academy labs, or the final exam at the time? Which version of Burp are you using?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.