The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Custom Extension for Whitelisting

Jamel | Last updated: Jan 29, 2020 11:22AM UTC

Burp Suite Pro v1.7.23 Is it possible to skip a certain link/URL for specific checks (e.g. CSRF, SQL Injection) during a scan, while remaining them ticked in Scanner Options? So for better visualization, I'll provide a scenario: In my web app, I have an API that doesn't check for CSRF Token. After the scan, Burp flagged that API as vulnerable to CSRF Attack. After that, I thought of creating custom Extension that will whitelist that API to CSRF Token, but I have no idea if this is achievable. Thanks!

Hannah, PortSwigger Agent | Last updated: Jan 29, 2020 11:25AM UTC