The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Control scope to only get from TLD and no external sites

Lynne | Last updated: Apr 06, 2022 07:56PM UTC

Right now I have a scope defined: foo.com BS is GETting stuff from there without a problem. Some URLs on foo.com reach out to external URLs like /google/pageads BS is getting stuff from the external URLs, too. Am I misunderstanding how scope control works? I *only* want to get responses directly from foo.com and not from /google/pageads I see the Exclude scope, but the external site count on foo.com is in the dozens at very least, and I don't know all of them. Do I have to specify exactly which URLs to ignore? what about wildcards? Can I exclude * and include foo.com to restrict the scope?

Ben, PortSwigger Agent | Last updated: Apr 07, 2022 09:57AM UTC