Burp Suite User Forum

Create new post

Potentially misconfigured headers from extension "Header Analyzer"

Einar | Last updated: Sep 13, 2016 09:31PM UTC

The "Header Analyzer" extension reports the following issue: Potentially misconfigured headers: Header name: x-xss-protection. Header value: 1; mode=block My response contains this header: X-XSS-Protection: 1; mode=block As far as I know, that is a correct header? Can anyone explain why this extension says it is "potentially misconfigured? Thanks

PortSwigger Agent | Last updated: Sep 14, 2016 01:07PM UTC

Thanks for this feedback. Burp extensions in the BApp Store are not written or maintained by the Burp team. We would recommend that you contact the extension's author to feed back issues like this, thanks.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.