Burp Suite User Forum

Create new post

Web application scanning

Ernesta | Last updated: Mar 04, 2021 11:00AM UTC

Hi, What web pages can I use for web application scanning with Burp Suite Pro? I am interested in web application scanning according to OWASP Top10 list. All scanning will be done for my school project.

Ben, PortSwigger Agent | Last updated: Mar 04, 2021 02:45PM UTC

Hi Ernesta, It is very important to stress that you should only be using Burp against sites where you have the explicit permission of the owner to do so. Using automated scanning tools against sites where you do not have permission is, in many places, a criminal offence so please be careful when you are using Burp. We have a test site, https://portswigger-labs.net, that can be used in order to test the functionality of Burp and you have our permission to use this site during your project. In case you are interested, there is some further information about how to use Burp to scan websites, along with a nice video, on the page below: https://portswigger.net/burp/documentation/desktop/scanning

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.