The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

False positives

Chris | Last updated: Nov 13, 2019 02:43PM UTC

I am getting too many false positives of "Content type incorrectly stated" vulnerability all the time. My last occurence is: '''The response states that the content type is font/x-woff. However, it actually appears to contain unrecognized content.''' The response starts with wOFF and some binary stuff is following. When issue the "file" command on that it says: Web Open Font Format, TrueType, length 83760, version 1.0 What method do you use to determine the response type??

Mike, PortSwigger Agent | Last updated: Nov 13, 2019 02:54PM UTC