Burp Suite User Forum

Create new post

Burp 2.x does not passively scan certain content types it did in 1.7

Seth | Last updated: Jan 28, 2019 04:17PM UTC

In Burp 1.7.x Burp would find issues like 'Email address disclosed' on non-HTML content types. For example if the following was served in 'emails.txt' with Tomcat: test@gmail.com fake@gmail.com Burp 1.7.x would find and report the 'Email address disclosed' issue. In Burp 2.x that is no longer the case. Burp will not show these in the passive audit task and therefore the issue will not get reported anymore. This also happens for other content types like CSS and JS. This also trickles down to extensions as the 'doPassiveScan' is not getting called for text, CSS and JS content types in my testing. I tested this using the Burp 1.7.37 installer and Burp 2.0.14beta installer on Windows.

PortSwigger Agent | Last updated: Jan 29, 2019 10:43AM UTC

Thanks for letting us know about this. This is a bug which we will resolve in a future version.

Burp User | Last updated: Feb 15, 2019 02:20PM UTC

This is fixed in 2.0.16.

Liam, PortSwigger Agent | Last updated: Feb 15, 2019 02:23PM UTC

Thanks for letting us know Seth.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.