Burp Suite User Forum

Create new post

Does Burp Suite Enterprise support checking for any malware within image files?

Glenn | Last updated: Jun 08, 2020 02:52PM UTC

This has been asked of me: something that might be using steganography or code hidden in EXIF metadata Thanks,

Uthman, PortSwigger Agent | Last updated: Jun 08, 2020 03:54PM UTC

Hi, This is not something that the scanner can detect natively. You can find a full list of the issues the scanner will search for here: https://portswigger.net/kb/issues. There are two extensions for Burp Pro that could work: - Image Metadata: https://portswigger.net/bappstore/3996aa01e0474b1a990db586a7f14ab7 - ExifTool Scanner: https://portswigger.net/bappstore/858352a27e6e4a6caa802e61fdeb7dd4 It looks like both have not been updated in a while but you can try those. Alternatively, you can write your own custom scanner checks using the Extender API. Again, this is only possible in Pro: - https://portswigger.net/burp/extender/api/ - https://github.com/PortSwigger/example-scanner-checks

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.