Burp Suite User Forum

Create new post

scan website header vulnerabilities

David | Last updated: Jan 23, 2021 05:29AM UTC

Hi. I encountered other web-scanning and they indicated some headers are exposed, and they suppose to be hidden. For example; header X-Powered-By was flagged as "issue" and it should be removed. But when i use this tool burp-pro, it never reported that x-powered-is an issue. I need this kind of checkings to be included. Is it part of the default setting, or do i miss any configuration? And for the owasps testing, do i also have to include the setting, or it is part of the default?

Uthman, PortSwigger Agent | Last updated: Jan 25, 2021 10:14AM UTC

Hi David, It does not look like that is included in our scanner issue database: - https://portswigger.net/kb/issues However, you can set up custom scan issues using the 'Burp Bounty, Scan Check Builder' extension (https://portswigger.net/bappstore/618f0b2489564607825e93eeed8b9e0a) To test the OWASP top 10, you can use the article below to assist you but we do not have any other specific recommendations on this: - https://portswigger.net/support/using-burp-to-test-for-the-owasp-top-ten You may be able to achieve testing through some manual tests and some automated ones with the scanner.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.