The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How can I check if the Infiltrator works properly?

Adrian | Last updated: Oct 05, 2016 01:21PM UTC

Hi there! I patched vulnerable demo Java application via Burp Infiltrator and then run spider + active scan against original web application and patched version. I got two different scan results. The fun fact is that the scanner found more vulnerabilities in non-patched version of the software (including out-of-band requests, SQLi etc.). How can I check that Infiltrator patch works properly (from Burp Suite point of view)? For example in the Acunetix .NET Acusensor I can send some kind of debug headers to the patched web application (ACU_HEADER if I remember correctly) and get the response with ACU_HEADER (then I know that in the deployment Acusensor has been installed correctly). Cheers!

PortSwigger Agent | Last updated: Oct 05, 2016 04:03PM UTC