Problem with multihost angularjs site

Mark | Last updated: Oct 28, 2015 06:03PM UTC

We have an angularjs/REST web app (IE11) at a client that works fine (no proxy) but is broken when burp is in the middle. The web page normally pulls in several js and css files from a second domain, also owned by the client. When we look at the target page, the foreign domain host is listed along with the paths to the included files, but they are in gray, indicating they were never fetched (and there are requests but no responses listed). No requests to the second domain are listed in the HTTP History tab (with all filtering off). However, we can manually pull up each 'include' page in the browser with no problem, and the request/response appears in the history once I have done this. What would cause this? N.B. We have 'Out-of-Scope Requests' set to suite scope, and all the pertinent domains and host names included in the scope list. Just as a check, the second domain *is* listed in the target tab when 'hiding out of scope items' is set.

Liam, PortSwigger Agent | Last updated: Oct 28, 2015 06:19PM UTC

HI Mark Thanks for your message. Have you installed Burp's CA Certificate? https://support.portswigger.net/customer/en/portal/articles/1783075-installing-burp-s-ca-certificate-in-your-browser You should also try restoring the default settings for "Out-of-Scope Request" options. Please let us know if you need any further assistance.

Burp User | Last updated: Oct 29, 2015 12:05PM UTC

The cert was the problem. There was a burp cert on the desktop of the test machine I was working on, but apparently no one had ever imported it. Thanks.

