The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

scan website header vulnerabilities

David | Last updated: Jan 23, 2021 05:29AM UTC

Hi. I encountered other web-scanning and they indicated some headers are exposed, and they suppose to be hidden. For example; header X-Powered-By was flagged as "issue" and it should be removed. But when i use this tool burp-pro, it never reported that x-powered-is an issue. I need this kind of checkings to be included. Is it part of the default setting, or do i miss any configuration? And for the owasps testing, do i also have to include the setting, or it is part of the default?

Uthman, PortSwigger Agent | Last updated: Jan 25, 2021 10:14AM UTC