The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CSRF Scanner not detecting CSRF token named ContactCsrfToken

Gaurav | Last updated: Sep 21, 2023 09:43PM UTC

Note: This issue was generated by the Burp extension: CSRF Scanner. Issue detail The request does not appear to contain an anti-CSRF token. However we are using a token such as the following: ContactCsrfToken=wL7Ai7Q6U1kAVSbSjm_dcxUaTrvVY-iJ_lSMKGJRY2MmjBpuOS Is CSRF scanner only looking to match known token strings? Is the token name above not matching? I came across https://github.com/PortSwigger/csrf-scanner/blob/master/BurpExtender.java which has a default token pattern match that seems to be missing case insensitive matches.

Dominyque, PortSwigger Agent | Last updated: Sep 22, 2023 08:46AM UTC