Burp Suite User Forum

Create new post

Coverage for penetration testing is 100% for my website.

Aasmeet | Last updated: Sep 24, 2021 02:01PM UTC

When I run an active/passive scan on a website then the burp suite automatically scans multiple tabs available on my website. Hi, However, each tab has multiple functionalities like search, pagination, download reports, filters, refresh button, view form, Add data, delete data, update data etc... I am not sure whether Burp Suite performs penetration testing for these functionalities on my website. So, I am unaware if my coverage for penetration testing is 100% for my website. Can you guide me on this query? Also, Can I save the passive scan mechanism that I had ran previously in the burp-suite, so that I can re-run the same scan for my future passive scanning?

Hannah, PortSwigger Agent | Last updated: Sep 27, 2021 02:50PM UTC

Hi Are you running a full scan (crawl and audit - Dashboard > New scan) on your site, or are you manually crawling your site through a proxied browser, and then auditing the selected items? If you have set up a specific scan configuration that you are using, then you can save this configuration to your configuration library by clicking on the "Save to library" checkbox and the "Save" button when you are editing your configuration. If you want the data to persist, then you would need to use a disk-based project file instead of a temporary project file.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.