Name is required.
Email address is required.
Invalid email address
Answer is required.
Exceeding max length of 5KB

Meaning of the 'Edited' column in 'Proxy / HTTP history'

NIcolas Grégoire Jan 16, 2020 10:55AM UTC

Hello,

from my experience as a trainer, the meaning of the 'Edited' column in 'Proxy / HTTP history' is quite often misunderstood. In fact, students' expectations are coherent, they just don't match the design choices made by Portswigger.

There are two builtin ways to edit the traffic going through the Proxy 1) manual modification when messages are intercepted 2) Match & Replace rules. In both scenarios, the modified entries appear in the history (resp. under names 'Edited request' and 'Auto-modified request'). However, the 'Edited' chekbox is checked only in the first case (manual modification of intercepted messages). A lot of people expect to have the column checked in both situations. The documentation states 'Flag whether the request or response were modified by the user', which is ambiguous https://portswigger.net/burp/documentation/desktop/tools/proxy/history

My proposal:
- check the column in both situations
- rename the column to 'Modified' (optional)

Thanks in advance,
Nicolas


Hannah Law Jan 16, 2020 02:43PM UTC Support Center agent

Hi Nicolas

I’ve put this in as a feature request to be further reviewed by the development team. We have a large backlog of requests at the moment, so we are unable to provide an ETA.


Post Your public answer

Your name
Your email address
Answer