Burp Suite User Forum

Create new post

discovery scan regards "301 moved permanently" as a success

Ian | Last updated: Apr 30, 2018 03:37PM UTC

I've tried using the "discovery" feature but tend to find it's not particularly useful because of its tendency to regard common methods of redirecting to login forms as a "success", meaning it fills the site map with false hits. At the moment I'm on a fairly unadventurous site and am getting "301 moved permanently" responses to any access to content that doesn't exist when I don't have a login. Many years ago in a support post you suggested you were going to add a feature to allow us to configure what is regarded as a "miss", but this feature is still not present and is badly needed.

PortSwigger Agent | Last updated: May 01, 2018 07:56AM UTC

Hi Ian, Thanks for getting in touch. As you've noticed, the Content Discovery feature is due some work. I'm not sure how exactly we'll approach this. While manual configuration of hit/miss rules would suit advanced users, what we may do instead is leverage the advanced diffing logic that Backlash Powered Scanner uses to do this automatically. In the meantime, I've coded you a quick extension that ignores 301 responses: - https://github.com/pajswigger/ignore-301 Let me know how you get on with this.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.