Burp Suite User Forum

Create new post

Type casting issue

Vytautas | Last updated: Apr 06, 2020 02:19PM UTC

Hi, There is a bug. When i define the scope (or exclude some links from the scope, to be exact) some underlying functionality LOWERCASES my input. For example, I want to exclude the following link from scope so that crawler does not hit it and thus does not invalidate my session. http://192.168.124.129/bWAPP/logout.php When I add it in the "Target->Scope :: Exclude from scope" the "bWAPP" gets lower-cased and thus ignores the actual URl (with the uppercase/mixed-case bWAPP). After excluding the url (which gets lower-cased) I see that the crawler finds and hits the UPPERCASED link and thus terminates the session making it impossible to crawl the authenticated part of the web app. Please let me know if you need more details for solving the bug.

Uthman, PortSwigger Agent | Last updated: Apr 07, 2020 07:19AM UTC

Hi, Have you tried using the advanced scope control in Target > Scope?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.