Burp Suite User Forum

Create new post

Recreate burp open redirection (dom-based) dynamic analysis

Huss, | Last updated: Jun 21, 2019 03:10PM UTC

We have a number of 'Open Redirection (DOM-based)' findings. In each case, the reported Request and Response look perfectly normal. The Dynamic analysis (DA) shows something completely different. When I Repeat the DA GET request, I still get the normal Response, not the error message shown in the DA. What is missing?

PortSwigger Agent | Last updated: Jun 24, 2019 10:18AM UTC

For dynamic analysis, the request and response just show Burp loading the JavaScript. At the bottom of the dynamic analysis tab, Burp will generate a proof of concept. Please try this to replicate the vulnerability. Be aware that it's not always possible to automatically generate a POC and some manual tweaking may be required.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.