Burp Suite User Forum

Create new post

ASP.NET ValidateRequest bypass + tuning

vpb | Last updated: Jun 16, 2015 07:19AM UTC

According to my experience Burp Suite doesn't check for this type of ValidateRequest filter bypass: http://www.jardinesoftware.net/2011/07/17/bypassing-validaterequest/ Would it be possible to add this to the Persistens XSS checks? (Sorry if I missed something) On a related note: Since ValidateRequest throws an exception when encountering typical XSS patterns many apps terminate the users session during scanner runs (if XSS checks are enabled). Would it be possible to fine-tune these checks so that they can detect if ValidateRequest filter is present?

PortSwigger Agent | Last updated: Jul 08, 2015 08:02AM UTC

Thanks for this request and apologies for the slow reply. We're planning some further enhancements to the XSS scanning logic in the near future and will look into how Burp can better handle ValidateRequest filters.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.