The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

"Session token in URL" false positive

Andrii | Last updated: Apr 17, 2016 08:42AM UTC

Hi, Burp Scanner v1.6.38 gave me false positive for "Session token in URL" without any reason, as I think. Take a look at following excerpt from report: https://drive.google.com/file/d/0B3mWggDv3CKZX0IzaDVfVUYzM1U/view?usp=sharing (you should open it with "HTML Editey" app or download to your file system).

PortSwigger Agent | Last updated: Apr 18, 2016 07:59AM UTC