The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scanning application - Angular 11 (frontend) and Spring Boot (backend)

Rafał | Last updated: Jun 16, 2021 12:04PM UTC

Can you help me explain if Burp Suite can scan applications based on Angular 11 (frontend) and Spring Boot (backend) technologies? Can it be done by free version or commercial version?

Uthman, PortSwigger Agent | Last updated: Jun 17, 2021 09:33AM UTC

Hi Rafał, Are you trying to scan a single-page application? Our development team is actively working on improvements for better single-page application support but the scanner does not handle this well at the moment. The scanner is only available in Burp Suite Professional and Burp Suite Enterprise. Please feel free to apply for a trial of either product below: - https://portswigger.net/burp/pro/trial - https://portswigger.net/burp/enterprise/trial

Rafał | Last updated: Jun 17, 2021 02:11PM UTC

Hi Uthman, I am trying to scan a SPA application. Is there a workaround this problem recommended by you? Maybe there is some way to test the REST-API serviced by the backend application? I have one more question. When buying a Burp Suite Enterprise license, can we also use the Burp Suite Professional version?

Uthman, PortSwigger Agent | Last updated: Jun 17, 2021 02:35PM UTC

Hi Rafał, Unfortunately, there are no workarounds since we need to make changes to the scanner itself. Our developers are actively working on this and we expect the first set of improvements to be released over the next few months. We'll keep this thread updated! For API scanning, you can check out the documentation below: - https://portswigger.net/burp/documentation/desktop/scanning/api-scanning - https://portswigger.net/blog/api-scanning-with-burp-suite Each product is sold separately but I would encourage you to apply for a trial of both so that you can see which suits your requirements best.

Rafał | Last updated: Jun 21, 2021 04:15PM UTC

My API is token secured (). Can Burp Suite scan a secured API?

Uthman, PortSwigger Agent | Last updated: Jun 22, 2021 08:26AM UTC