Burp Suite User Forum

Create new post

How to pentest a web site that behind reverse proxy?

samiux | Last updated: Oct 04, 2015 11:49AM UTC

Is it possible to pentest a web site that behind reverse proxy? If yes, how to?

PortSwigger Agent | Last updated: Oct 05, 2015 07:57AM UTC

Normally, a reverse proxy receives regular incoming requests addressed at the public domain name, and relays these to a suitable internal host. This might be done for various purposes, such as load balancing a number of servers behind a single public endpoint. In this situation, you don't need to do anything different to test the target, and there might be no evidence that the proxy is even present.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.