Burp Suite User Forum

Create new post

Incorrect work of Passive Scan Issues

Sergey | Last updated: Nov 27, 2020 10:40AM UTC

I began to actively use extensions that analyze content in a passive mode, and noticed that in the latest version (and maybe earlier) there is a problem with creating an issue. For example, the Software Version Reporter extension stops adding new issues despite the fact that the log shows that the super.processIssues function is being called. Apparently, this also applies to built-in passive checks. The bug can appear both in a few minutes after the start of work, and in a few hours. The easiest way to detect it is to write a bot in selenium, proxy it through a burp, and use it to go through the list of sites. From some point on, passive checks stop creating an issue. Example: https://i.imgur.com/v51lZm0.png

Michelle, PortSwigger Agent | Last updated: Nov 27, 2020 03:48PM UTC

Thanks for your message. Can I just confirm, do you see this behavior with more than one extension? Do you only see this behavior when using extensions, have you ever seen this when performing a passive scan within Burp?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.