Burp Suite User Forum

Create new post

Good XSS detection

Dennis | Last updated: May 29, 2015 03:06PM UTC

I'm somewhat disappointed. I conducted an nessus scan on a host, without entering any information. It found an XSS. When I did an active scan of the same host with Burp, Burp did not. It is a really easy to find XSS. I'm pretty amazed about this, since Burp is my choice for Web Testing. Please do have at least the level of accuracy as a regular nessus engine does when it comes to web testing.

PortSwigger Agent | Last updated: Jun 01, 2015 08:39AM UTC

We believe that Burp's XSS detection is highly capable and surpasses the capabilities of general purpose scanning tools. Are you sure you definitely scanned the actual request containing the XSS (e.g. the form submission not the loading of the page containing the form)? If so, please can you provide details of the vulnerability that Burp fails to report, including relevant request/response extracts, and we'll investigate? Thanks.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.