Burp Suite User Forum

Login to post

Sanning report issue

Bappe | Last updated: Dec 17, 2019 10:07AM UTC

When i attempt an automated scan in same target and same scanning configuration the report become difference between following situation, (a) scan without any pause or restart burp then the result is 10 issues [for example] (b) scan with few pauses and restart burp then the result is 9 issues.

Liam, PortSwigger Agent | Last updated: Dec 17, 2019 10:35AM UTC

It's not clear why this difference in results might have occurred. How many times have you run this test? Are you able to reproduce this consistently? Which version of Burp are you using? Are you able to manually verify the results of the scan? The actual impact and validity of any issue will always depend on the nature of the application functionality and the business context in which it appears. Hence, issues should always be manually reviewed based on the tester's knowledge of the application.

Burp User | Last updated: Dec 17, 2019 11:39AM UTC

hi liam, actually i am using burp suite pro 2.1.06. and i have scanning multiple times. the result is different under same project when i pause the scan and restart burp then again resume the scan.

Liam, PortSwigger Agent | Last updated: Dec 17, 2019 12:06PM UTC

Are you able to manually verify the results of the scan? Is this a legitimate issue tha Burp is missing? Is it possible that the issues are being consolidated?

You need to Log in to post a reply. Or register here, for free.