The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Skip fields named 'password' by default in Active Scans

Andrew | Last updated: Nov 30, 2020 11:33PM UTC

During a test where a username and password was passed in for every request to a web-service, I noted that it seemed reasonable to skip fields named 'password' by default in active scans. I added that to a comprehensive library scan definition, but it seems like that should be the default for scans. Scanning the password field can definitely lead to lockouts. I'm not sure there are tests specific to fields named password that could merit not having that scanned by default.

Liam, PortSwigger Agent | Last updated: Dec 02, 2020 09:12AM UTC