Burp Suite User Forum

Create new post

How do i can audit selected items from target sitemap via command-line or api?

Valentyn | Last updated: Jan 28, 2020 03:55PM UTC

Hello, We stuck at the problem with burp integration into our CI pipeline. I found extension and API to start 'crawl and audit', but in our case, we are using the 'audit selected items' option from the target sitemap. How I can start scanning via cl or API with this option? Or at least there is a way to change sitemap base URL (Example: test.test/ -> test1.test) Best regards, Valentyn

Ben, PortSwigger Agent | Last updated: Jan 28, 2020 04:37PM UTC

Hi Valentyn, Unfortunately, you cannot initiate an audit only scan on items that are already in your target sitemap. A scan initiated via the API is conducted as a brand new scan and, therefore, has to go though both a crawl and audit phase. Have you had a look at Burp Suite Enterprise? This has been specifically designed for integration with your CI/CD pipeline and offers unlimited scalability - https://portswigger.net/burp/enterprise Please let us know if you require any further information.

Burp User | Last updated: Jan 29, 2020 04:37PM UTC

Hi Ben, We just declined from Burp Enterprise licenses due to they didn't meet our needs. https://support.portswigger.net/customer/en/portal/questions/17663952-how-do-i-can-use-sitemap-and-macros-from-professional-in-enterprise-version-?new=17663952

Burp User | Last updated: Jan 29, 2020 04:48PM UTC

Hi Ben, We already tried Burp Suite Enterprise, but unfortunately, there is only a 'crawl and audit' option, also no extensions, no sitemap, etc. Burp Suite Pro gives us much more scalability. Maybe there are some other options? In our case crawl works really bad and takes a lot of time.

Ben, PortSwigger Agent | Last updated: Jan 30, 2020 10:25AM UTC

Hi Valentyn, Thank you for the clarification. Unfortunately, the functionality of the REST API is limited and is not currently able to perform the task that you require. Other users have requested the ability to perform an audit-only scan through the REST API so we do have this feature in our development roadmap but we cannot provide an ETA of when it might be implemented. Please let us know if you require any further information.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.