Burp Suite User Forum

Create new post

Static and Dynamic scan of .NET MVC web application coding in development environment

Ahmed, | Last updated: Aug 08, 2018 05:44PM UTC

Hi, I am planning to buy two licenses of Burp Professional. Does Burp professional license includes all the modules/functionalities including static/dynamic scanning of developers actual coding. If not what should I need to buy to get the dynamic/static scanning of developers coding. Currently we use F5 WAF, and it gives errors of unsafe coding. My plan is to use the Burp during development so that we won't get unsafe coding error from F5... Any suggestion will be greatly appreciated, and anticipated. We looked into several tools and Burp is our first choice.

Liam, PortSwigger Agent | Last updated: Aug 09, 2018 10:53AM UTC

Burp Suite Professional provides all of the functionality you will have read about in your tool review. Burp's static code static analysis is currently limited to JavaScript. - https://portswigger.net/blog/burp-gets-new-javascript-analysis-capabilities It's also worth noting that our Infiltrator tool performs IAST testing of .NET applications: - https://portswigger.net/blog/introducing-burp-infiltrator Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.