Burp Suite User Forum

Create new post

Strict transport security not enforced without request/response

Tiago | Last updated: May 31, 2017 12:55PM UTC

The Strict transport security not enforced issues do not show a request/response. This does not make any sense, there was at least one response that had no HSTS header for Burp to show that issue, so it makes sense to report which response cause that. Actually you could report that for all the responses that lack the header, similar to what is done to other issues.

PortSwigger Agent | Last updated: May 31, 2017 01:02PM UTC

Thanks for your message. We agree that this would be a useful feature. In fact, we already have this in our development backlog, and it will be in a future edition. We don't believe that reporting all responses that lack the header would be useful for most users. The header is usually set at a server level, so reporting all instances would greatly increase the volume of output with minimal benefit. Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.