The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

test Cross-site scripting in scanner using encoded payloads

APOORV | Last updated: Sep 13, 2017 08:59PM UTC

Hello , I observed that the scanner was testing reflected XSS issues using payloads that are not URL encoded. This sometimes results in false positives as all modern popular browsers URL-encode special characters in address bar by default. Please let me know your thoughts on this. Nevertheless, Burp is the single greatest tool for a web pentester. Thank you :)

PortSwigger Agent | Last updated: Sep 14, 2017 08:23AM UTC