Burp Suite User Forum

Create new post

Exclude from crawl scope using query string (burp 2.0.13)

Wouter | Last updated: Dec 07, 2018 11:04AM UTC

Hi, How can I, for example, exclude the following URL from the crawl scope: https://example.com/main.php?logOut=true Thanks in advance

Liam, PortSwigger Agent | Last updated: Dec 10, 2018 11:12AM UTC

Wouter, you should enter the URL in to the Target > Scope > Exclude from scope function. If you've tried this and it's not working, could you describe the behavior you are encountering.

Burp User | Last updated: Dec 10, 2018 11:56AM UTC

Liam, the query string is NOT added to the excluded scope. The target scope does show the excluded URL, but the query string is not present.

Liam, PortSwigger Agent | Last updated: Dec 10, 2018 01:48PM UTC

Thanks for clarifying. We'll bring this up as a potential feature request.

Liam, PortSwigger Agent | Last updated: Dec 10, 2018 02:47PM UTC

Just to follow up, we've added a note to our dev backlog to explore adding this functionality. Unfortunately, we can't provide an ETA.

Liam, PortSwigger Agent | Last updated: Apr 08, 2019 01:37PM UTC

Hi Wouter. We haven't made any progress with this feature, it is still in our backlog. Have you found Burp 2's crawler is better at managing this use case? It should be reestablishing a session when it is logged out.

Burp User | Last updated: Jul 29, 2019 07:48PM UTC

Hi Liam, any updates about this feature?

PMwxVLDHhy6oiP | Last updated: Aug 11, 2021 08:27AM UTC

Has this been implemented yet? I need to block requests of this form: ``` https://website.com/index.php?action=lockAccount ``` Reestablishing the session does not work, due the account being locked out.

Ben, PortSwigger Agent | Last updated: Aug 11, 2021 02:05PM UTC

Hi, This proposed functionality is still in our development backlog, I am afraid. It is something that we are currently monitoring the demand for so that we can potentially add it to our development roadmap but we still do not have an ETA of when this might be implemented. I have added your interest in this to the existing entry in our development system so that we have an up-to-date record of the level of user interest in this particular functionality. As always, we will update this forum thread if we do have any further news to share.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.