Burp Suite User Forum

Create new post

Scope Bug

amarionette | Last updated: Mar 18, 2021 08:05PM UTC

Hello, Issue: Burp Suite does not respect the defined scope specified in "Target Scope". The issue is if the specified in-scope URL appears in a GET parameter (or possible elsewhere on the same line) of a site that is not in-scope, the application will consider the URL as in-scope. For example: Add https://myinscopedomain.com to the "Target Scope". Advanced Scope control is not checked. www.facebook.com?url=https://myinscopedomain.com will show up as in-scope in "Proxy History"

Michelle, PortSwigger Agent | Last updated: Mar 19, 2021 12:15PM UTC

Thanks for your message.

I've just been trying to replicate this here but I'm not seeing the same behavior so could be testing this slightly differently. Can you email support@portswigger.net with some screenshots of your Target -> Scope tab and the Proxy History tab showing the requests, please?
Is the Proxy History tab confirming that logging of out-of-scope traffic is disabled?
Which version of Burp are you using?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.