Burp Suite User Forum

Create new post

Scan is not Enumerating Subdirectories

Robert | Last updated: Nov 04, 2021 08:58PM UTC

Hello, I am attempting to scan my testing environment with the Burp Scanner. Unfortunately, even after using Burp Navigation Recorder and supplying login credentials to the scan, it does not make it past the login page. I was wondering if anyone had any ideas why this might be the case. Even when adding those subdirectories to the scan's detailed scope configuration- it does not do it. I attempted to run in a headed browser and analyzed the authenticated scan and after successfully authenticating- the page that it attempts to load redirects to a :blank page.

Uthman, PortSwigger Agent | Last updated: Nov 05, 2021 11:01AM UTC

Hi Robert,

Thanks for reporting this. Please email us with the information below so that we can assist you further.

If you are using Pro:

  • A screenshot of your scope (URLs to Scan and any Included/Excluded URLs) in the scan wizard
  • Detail on any scan configurations you are using
  • The login script JSON retrieved from the navigation recorder extension - please share exactly what you are pasting and whether you have modified the JSON
  • Screenshots of the event log
  • Whether you have any extensions enabled
  • Screen recording of the login sequence replayed
  • Screen recording of a headed crawl
  • Crawl debug log.- you can enable debug mode via Dashboard > New scan > Scan configuration > New > Crawling > Crawl Optimization > click the cog button > Enabling logging

If you are using Enterprise:

  • Scan debug and scan event log retrieved from the Reporting & Logs tab
  • A scan report
  • The support pack covering the duration of the scan from start to finish
  • Screenshots of your site configuration
  • Detail on any scan configurations you are using
  • Whether you have any extensions enabled

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.