The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Site map - Filter by Tools

Andrej | Last updated: Oct 25, 2018 08:52AM UTC

In the Site Map tree, I can see many payloads (in folder and file names) which were used by Active scanner (alone, or by some extension during the Active Scan). Such payloads are: %00grqjw%22a%3d%22b%22sc35f %00prompt(1) ..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5c..%5cwindows%5cwin.ini%00index This results from having "URL path filenames" and "URL path folders" check in the Attack Insertion Points, which I do want to check for, but I don't want them to appear in the SiteMap itself. Would it be possible, in the future, to filter out these attack payloads? Or rather, to filter only those requests, which were made through the Proxy (which would effectively hide undesired ones). Thanks

Liam, PortSwigger Agent | Last updated: Oct 25, 2018 12:26PM UTC