The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Is there a way to determine which scanner check produces a specific HTTP request?

Alla | Last updated: Dec 29, 2023 08:40AM UTC

I am scanning an application and as a result the application crashes. From the Logger tool I can see which request most likely caused the crash (because the application started responding with errors after that request). I would like to modify the scan policy to remove the issue check that is sending this request, to be able to complete the scan without crashing the application. How can I determine which issue is sending the request? The request has the following string injected "\r\nBCC:mkaz8oiksqrxye8uf6t9ltaeh5nybvznsbjyamz@oastify.com\r\ntck: f", so I suspect it is SMTP header injection, but I would like to be sure.

Syed, PortSwigger Agent | Last updated: Jan 04, 2024 04:11PM UTC