Burp Suite User Forum

Create new post

Burp Store and burp app validation

John | Last updated: Nov 28, 2017 09:41AM UTC

Hi, Regarding the burp store, do you do any check regarding the content of the burp extension? How can we guarantee that there are 100% safe and no traffic will be sent to 3rd party? Appreciate your response. Thank you.

PortSwigger Agent | Last updated: Nov 28, 2017 09:43AM UTC

Hi John, Thanks for your message. We review all extension in the BApp store, checking for suspicious code and security vulnerabilities. We don't ban connections to 3rd party servers. A number of extensions do this by design, for example to fetch the latest definitions of vulnerable software. Normally we would reject extensions that send unexpected or excessive data to external servers. With everything in security, nothing is 100% safe.

Burp User | Last updated: Nov 28, 2017 11:26AM UTC

Thank you for clarifying.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.