Burp Suite User Forum

Create new post

Skip fields named 'password' by default in Active Scans

Andrew | Last updated: Nov 30, 2020 11:33PM UTC

During a test where a username and password was passed in for every request to a web-service, I noted that it seemed reasonable to skip fields named 'password' by default in active scans. I added that to a comprehensive library scan definition, but it seems like that should be the default for scans. Scanning the password field can definitely lead to lockouts. I'm not sure there are tests specific to fields named password that could merit not having that scanned by default.

Liam, PortSwigger Agent | Last updated: Dec 02, 2020 09:12AM UTC

Thanks for your message, Andrew. Some vulnerabilities like SQL injection and LDAP injection are relatively common in the password field so we believe it needs to be scanned by default.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.