Burp Suite User Forum

Create new post

In the active scan, sqli and judgment has a problem

hackone | Last updated: Nov 20, 2016 01:59AM UTC

My English is not good. In the active scan, (and 1=1) and (and 1=2 ) The returned result is different but the scan Not detected There is a problem

PortSwigger Agent | Last updated: Nov 21, 2016 09:14AM UTC

Burp does send SQLi payloads containing injected Boolean conditions, and looks for differential responses. The check is repeated several times to ensure the responses correlate with the payloads, so if there is any unreliability the issue might be lost. Also, if the difference is very subtle, Burp might overlook it.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.