Burp Suite User Forum

Create new post

Viewing VIEWSTATE in responses as well as requests

Andrew | Last updated: Apr 29, 2015 12:08PM UTC

The "Viewstate" tab shows up on requests with VIEWSTATE in them, and decodes them nicely. I can't seem to get it to show up for responses though. Whilst the next request nearly always contains the previous response, it would be good to be able to see it natively.

PortSwigger Agent | Last updated: Apr 30, 2015 03:21PM UTC

The ViewState tab is intended to display for relevant responses (where a form contains a hidden ViewState field). This is working in our testing. If there are any features of the responses you are seeing which might prevent Burp from locating the VS, please let us know the details and we'll try to get Burp to correctly identify it.

Burp User | Last updated: Aug 20, 2019 05:11AM UTC

ViewState: It shows Background structure of application code. An attacker can use it to re-write the code.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.