The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

cookie flags are raised in burpscan but not in manual testing.

Ryan | Last updated: May 29, 2023 04:30AM UTC

burp scanner keeps raising the issue(s): - TLS cookie without secure flag set - Cookie without HttpOnly flag set. However, when replicating the same request manually (either by closing the session and re-opening, or private browsing), it was noted that the set-cookie headers all have the secure and httponly flags set on the cookies. only the ones in the burp issues do not have the flags. why is that so? appreciate any input.

Michelle, PortSwigger Agent | Last updated: May 30, 2023 11:01AM UTC