Burp Suite User Forum

Create new post

Cross-site request forgery - ignore date response header

Ed | Last updated: Dec 07, 2016 01:23PM UTC

Hi, I'm receiving a lot of false positives as nginx is sending the Date header - which is obviously different each time the scanner tries a new combination - so Burp is highlighting it (albeit tentatively). Is there any way to tell the scanner to ignore the date response header? Thanks, Ed

Liam, PortSwigger Agent | Last updated: Dec 08, 2016 04:48PM UTC

Hi Ed Thanks for your message. You can use Burp's Scanner > Options > Attack Insertion Points functionality to skip HTTP headers.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.