Burp Suite User Forum

Create new post

Collaborator - False positiv

Antoine | Last updated: Jun 25, 2021 12:37PM UTC

If the remote server do a HTTP request to RANDOMSTRING1.burpcollaborator.tld and the request contains RAMDOMSTING2.burpcollaborator.tld (for example in a POST value), the collaborator will report two HTTP requests as received from both domains. However, the request reported as received on RAMDOMSTING2.burpcollaborator.tld was the one sent to RANDOMSTRING1.burpcollaborator.tld.

Michelle, PortSwigger Agent | Last updated: Jun 25, 2021 03:03PM UTC

Thanks for your message. To help us picture what you're describing could you send some screenshots to support@portswigger.net, please? Are you seeing this when Burp Scanner finds issues or are these requests you are generating for your own manual testing?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.