Burp Suite User Forum

Create new post

What is abuse of functionality reported by Burp suite

Sai | Last updated: Mar 24, 2018 04:27PM UTC

Our security team has reported something called [What is abuse of functionality], by which the user entry can be altered to some other value, even though we have validation for it. Lets say, one can choose max next 30 days but using burp suite they could change it beyond that. Please explain what exactly this attack is . How do I reproduce it without Burp.And what is the fix for it. I am not finding any documentation for it. Please help.

PortSwigger Agent | Last updated: Mar 26, 2018 07:18AM UTC

Hi Sai, Thanks for your message. I think your security team is reporting that you are relying on client-side validation, and not repeating this validation on the server. We have some instructions on how to reproduce that here: - https://support.portswigger.net/customer/portal/articles/1964212-using-burp-to-bypass-client-side-javascript-validation Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.