Burp Suite User Forum

Create new post

How to actively scan list of items

Andrej | Last updated: Nov 20, 2018 01:56PM UTC

I have a list of URLs and parameters in form of great many URLs. I want to actively scan all of these using Burp. However, it seems I need to either request such URLs through Burp Proxy, or Intruder. Is there any option like Extender, or some file import, which would allow me not to request these URLs in the first place and still to be able to actively scan them? Something like automatically adding millions of URLs without requesting them first.

PortSwigger Agent | Last updated: Nov 20, 2018 03:05PM UTC

One way to do this is to write a quick script that uses wget on each URL, proxying through Burp. You could enter the full list as seed URLs when creating a scan. However, this will do a crawl & audit, resulting in many more pages being discovered.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.