The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Extend SQL recognition to responses

Veres-Szentkirályi | Last updated: Oct 19, 2018 09:16AM UTC

The Active scanner in Burp already identifies SQL statements within queries as potential SQL injection vulnerabilities. However, some applications log the executed SQL statements in the HTML output as comments or in an HTML element hidden with CSS. So just by enabling the already existing algorithm to detect SQL statements within responses as well (not just requests), Burp could detect such information leaks about the database backend.

PortSwigger Agent | Last updated: Oct 19, 2018 02:53PM UTC