The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Replace URL in responses during a scan

Ilia | Last updated: Apr 18, 2023 02:36PM UTC

Hi there, I'm testing a local instance of a web application using Burp Suite Pro 2023.3.2. As I need to test a copy of a web application that is used in production, all the links in web pages that I receive from the locally installed server contain public URLs from the production server. I need to replace these public URLs with local ones. For example, I receive a web page with a button that redirects to href="https://myapp.com" and I want to replace it with href="https://192.168.178.141". The reason for this is that during a scan the crawler includes the public URLs in the scope and I don't want to scan the application in production. The same pages exist on my local server, so I want Burp to visit them too, but locally. I've already tried using the proxy's Match & Replace feature, and it works perfectly for manual crawling using the Burp browser. However, it doesn't work for scanning: Burp keeps receiving and scanning web pages with public URLs. Is there anything I'm missing that I should enable to replace the response body content during scans? Thanks, Ilia

Hannah, PortSwigger Agent | Last updated: Apr 18, 2023 04:20PM UTC