The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Session Token in URL

Elefterios | Last updated: Apr 15, 2021 04:05PM UTC

This vulnerability was generated by a response from and an F5. I am getting these quite often as more of the customers are using this technology. We have talked to their development team, and the Burp scanner is creating the message after scanning. The report will display: HOST - url PATH - /my.policy_nonce The my.policy is hosted by preventing unauthorized users from entering the network. The '_nonce' is not hosted by the customer. Would this be a false positive generated by Burp? Why is this happening and how can it be remediated in order to pass the information to the customer?

Uthman, PortSwigger Agent | Last updated: Apr 16, 2021 06:19AM UTC