Do spider inserts data as well ?

Dhaval | Last updated: May 01, 2018 09:33AM UTC

Hi I was crawling a site using burp spider, However I saw observed that spider has given some data in "Search field" and in some other fields as well. Do spider inserts any data ?

Liam, PortSwigger Agent | Last updated: May 01, 2018 09:33AM UTC

Burp Spider uses various techniques to crawl application content, and by default it will follow all in-scope links, submit forms with dummy data, and make additional requests (for robots.txt, directory roots, etc.). In some situations, running an automated spider in this way can result in unintended consequences, such as registering new user accounts, generating feedback emails, or changing other application state. You should use any automated tools with caution, if possible against only non-production systems. You should also closely review the Spider settings before use, and ensure that these are suitable for your application and your requirements. - https://portswigger.net/burp/help/spider_using

