Burp Suite User Forum

Create new post

Disabled agent can scan sites!

chandraveer | Last updated: Nov 29, 2018 06:46AM UTC

I am evaluating Burp Enterprise. From the Agents tab, I disabled one of my agents. Keeping a site on scan, I observed that the site was being scanned on that disabled agent. How is this possible?

Liam, PortSwigger Agent | Last updated: Nov 29, 2018 09:01AM UTC

Chandraveer, how did you disable the agent? How did you observe that it is still active?

Burp User | Last updated: Nov 29, 2018 10:44AM UTC

I disabled agent from 'Agents' tab in the top right corner. There is a switch for Enable/Disable aligned with each agents. Just turned off that switch and agent got diabled. I put a site for scan; clicked on it; in the scan detail, I found that disbled agent in 'Agent:' section.

Liam, PortSwigger Agent | Last updated: Nov 29, 2018 10:53AM UTC

We're unable to reproduce this in our testing. The agent should remain in the Agents section but should be "grayed out". Are you able to reproduce the behavior consistently?

Burp User | Last updated: Nov 29, 2018 01:33PM UTC

I am unable to reprdouce now the same issue. What I observed was- After a site goes for scan via an agent, if you disable/grey out the agent, the scan doesn't stop once it catches an agent.

Liam, PortSwigger Agent | Last updated: Nov 29, 2018 01:37PM UTC

We'll continue testing. Let us know what the steps are if you manage to reproduce.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.