Burp Suite User Forum

Create new post

Crawler does not crawl through websites thoroughly

Joseph | Last updated: Nov 03, 2022 08:31AM UTC

Greetings, My team is subscribed to Burp Suite Professional and recently I ran some test on the crawler to testify on its accuracy that it is good enough to run automated scan. We've configured the crawler setting to show the headed browser during scan. We've noticed the crawler does not navigate through every tabs on a single page application. We have also tried quite a few different crawler configurations such as setting the crawl strategy to 'most complete' and maximum link depth. Few months back, our team has also tried out the trial version of Burp Suite Enterprise and crawled results were somewhat similar. We've decided to continue testing Burp scanner's reliability to thoroughly scan applications. My team has tested the crawler on a few application however none of them are accessible to the public network. One of them is a self-hosted OpenCart application deployed with docker compose. If you would like to run test on the application, you can deploy it yourself using this link: https://hub.docker.com/r/bitnami/opencart/

Liam, PortSwigger Agent | Last updated: Nov 03, 2022 09:27AM UTC

Thanks for your message and investigation into Burp Crawler. We'll pass on your message to our Scanner development team and let you know if there are any configuration settings or improvements that we can make to help Burp crawl this application effectively.

Joseph | Last updated: Nov 09, 2022 08:54AM UTC

Any update for this issue?

Liam, PortSwigger Agent | Last updated: Nov 09, 2022 01:12PM UTC

Hi Joseph. Thanks for following up. We have a piece of work to fix issues highlighted from some react scoping work we have done. I've passed on the test application you brought to our attention to the project lead. Unfortunately, we can't currently confirm the scope and timeline for this work.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.