Burp Suite User Forum

Create new post

Spider treating active scan URLs with injected parameter queries as new urls to spider.

Matt | Last updated: Aug 16, 2016 04:08PM UTC

I built an extension that successfully spiders the application, but I have a problem where when active scanning starts in earnest, eventually it starts adding injected URLs into the scanning scope, thus duplicated the amount of work that needs to be done. I cannot find a configuration to shut off the behavior of identifying a URL with query params as a unique URL. I know that OWASP's ZAP has a setting like this. Or is there something else I'm missing?

PortSwigger Agent | Last updated: Aug 17, 2016 11:16AM UTC

Burp's native functionality doesn't add any Scanner-generated URLs containing attack payloads into the site map, or add them to the scan queue. Is your extension hooking HTTP requests made by the Scanner and processing them in some way, with the result that they are added to the site map or the scan queue?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.