The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

[Minor False Positive] Strict transport security not enforced when HTTP 30x encountered

Dr. | Last updated: Jun 08, 2021 09:48AM UTC

Hi, I have several instances on the dashboard which claim to have a HSTS problem but burpsuite obviously connected to the instance before. Example of a full response header: HTTP/2 304 Not Modified Date: Tue, 08 Jun 2021 07:17:09 GMT Server: Apache Etag: "097914b232bd37a30b988c5e7c90ae93b" Expires: -1 Cache-Control: must-revalidate, private Using 'copy as curl command' and curling the response shows the HSTS header correctly, along with a HTTP 200. It's not something one needs to worry about very much but I guess this should be easy to avoid. Cheers, Dirk

Uthman, PortSwigger Agent | Last updated: Jun 08, 2021 12:47PM UTC