The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Input returned in response (reflected) - detection in response header exclusion

Andrej | Last updated: Jan 03, 2018 03:04PM UTC

I have an environment in which there is request URI always reflected in the response “x-request-path” header. Would it be possible to have an option in Scanner -> Options -> Scan Issues -> Edit detection methods? I would like to see all the instanced in Body (which could lead to XSS or other issues), but at the moment I have too many false positives (1 for each parameter + URL path filename + name if an arbitrary supplied URL parameter). An example: GET /?_=1514990468889osofgagz54 HTTP/1.1 Response: HTTP/1.1 200 OK connection: close content-type: text/html;charset=UTF-8 date: Wed, 03 Jan 2018 14:59:45 GMT ... x-request-path: /?_=1514990468889osofgagz54 ... Thank you

Liam, PortSwigger Agent | Last updated: Jan 08, 2018 08:08AM UTC