Burp Suite User Forum

Create new post

Scan for trace.axd

Josh | Last updated: Oct 29, 2021 05:47PM UTC

Hi, I'm new to using Burp Suite and we found that in an application that trace.axd was on and could possibly disclose unwanted information. Is there a way to crawl and find if is exists? Or is there a module or add-in that would do this? Any help would be appreciated. Thanks in advance.

Ben, PortSwigger Agent | Last updated: Nov 01, 2021 11:55AM UTC

Hi Josh, Identifying whether ASP.NET tracing is enabled is one of the audit checks available within Burp and will be being used in a default scan - the details of this issue are noted below in the Burp Vulnerability Knowledge Base below: https://portswigger.net/kb/issues/00100280_asp-net-tracing-enabled

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.