The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How to scan a website which reply output in a javascript messagebox

Lalinda | Last updated: Dec 03, 2022 04:22AM UTC

I am new to the burp suite and I am trying to scan a website that is known to have error-based sql injection. The issue is the SQL error message comes in a javascript alert box. Therefore burp suite does not pick that up and generates the report as nonvulnerable. Is there a workaround to change this and consider javascript alert box reply also.

Hannah, PortSwigger Agent | Last updated: Dec 05, 2022 04:22PM UTC

Hi Could you tell me the version of Burp that you are using? If you run "Help > Health check for Burp's browser", does the check complete successfully, or are there any issues?

Khaled | Last updated: Dec 06, 2022 01:18AM UTC