The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Cross-domain script include issues ignore subresource integrity attributes

Veres-Szentkirályi | Last updated: Jun 17, 2016 03:05PM UTC

Cross-domain script include issues are useful, however they ignore whether the site uses subresource integrity (SRI) attributes. If so, the part that says "trusting the domain's own security to prevent an attacker from modifying the script to perform malicious actions" is not accurate since if the content changes, the cryptographic hash would change, thus modern browsers won't include it. More info: https://developer.mozilla.org/en-US/docs/Web/Security/Subresource_Integrity

PortSwigger Agent | Last updated: Jun 17, 2016 03:26PM UTC