Burp Suite User Forum

Create new post

Excluding pages from Burp Pro scanner by parameter value?

Jeremiah | Last updated: Apr 19, 2022 06:28PM UTC

Is it possible to exclude entire requests from the Burp Pro scanner if one of the request parameters/parameter values matches a certain string/regexp? I don't want to ignore the insertion point, I want to exclude the entire request. Examples would include things like victim.com/admin?action=delete&what=everything or victim.com/admin?user=123&delete=true. In these cases, excluding requests with a parameter/value matching "delete" would make scanning more useful.

Hannah, PortSwigger Agent | Last updated: Apr 20, 2022 08:14AM UTC

Hi When you say exclude the request, do you mean not use it in audit, or never crawl it at all in your scan?

Jeremiah | Last updated: Apr 28, 2022 08:23PM UTC

Hannah, Thanks for your response. Ideally, I'd like to exclude it from the crawl, but even excluding it from the audit would be okay.

Hannah, PortSwigger Agent | Last updated: Apr 29, 2022 09:50AM UTC

Hi Jeremiah

You could try using the BApp Store extension "Reshaper" to drop requests when they match specific conditions.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.