The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Suggest updating header recommendations in Advisories

Emily | Last updated: Mar 27, 2024 04:46PM UTC

From "Frameable response (potential Clickjacking)", advisory recommends adding X-Frame-Options header but is it better to recommend Content Security Policy as the first choice and X-Frame-Options for compatibility support. From "Cacheable HTTPS Response", advisory recommends adding "Pragma: no cache" but it could maybe caveat that this header is deprecated and only used for HTTP/1.0 support.

Syed, PortSwigger Agent | Last updated: Mar 28, 2024 11:51AM UTC