The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Excluding pages from Burp Pro scanner by parameter value?

Jeremiah | Last updated: Apr 19, 2022 06:28PM UTC

Is it possible to exclude entire requests from the Burp Pro scanner if one of the request parameters/parameter values matches a certain string/regexp? I don't want to ignore the insertion point, I want to exclude the entire request. Examples would include things like victim.com/admin?action=delete&what=everything or victim.com/admin?user=123&delete=true. In these cases, excluding requests with a parameter/value matching "delete" would make scanning more useful.

Hannah, PortSwigger Agent | Last updated: Apr 20, 2022 08:14AM UTC

Hi When you say exclude the request, do you mean not use it in audit, or never crawl it at all in your scan?

Jeremiah | Last updated: Apr 28, 2022 08:23PM UTC

Hannah, Thanks for your response. Ideally, I'd like to exclude it from the crawl, but even excluding it from the audit would be okay.

Hannah, PortSwigger Agent | Last updated: Apr 29, 2022 09:50AM UTC