Unlock enhanced API scanning with Burp Suite Enterprise Edition  –  Learn more

Professional 1.6.37

12 February 2016 at 15:14 UTC

SHA256: {SHA FROM OPTION GOES HERE} MD5: {MD5 FROM OPTION GOES HERE}

This release gives the Scanner the capability to report all instances where user input is returned in application responses, both reflected and stored:

The information gathered is primarily of use to manual security testers. Some applications contain numerous instances of input retrieval, since it is very common for the entire URL to be reflected within responses. For these reasons, the new Scanner checks are off by default, but can be turned on in the Scanner options: