Skip to content

Qualys Expands Web App Scanning: Now Import Any Finding to Burp Repeater

Qualys' new update lets you import all WAS findings to Burp Repeater. Perfect for manual validation, it supports both Professional and Community Edition users.

In this image I can see a box full of cookies. To the cap of the box there is some text and design...
In this image I can see a box full of cookies. To the cap of the box there is some text and design on it.

Qualys Expands Web App Scanning: Now Import Any Finding to Burp Repeater

Qualys has released version 2 of its Web Application Scanning (WAS) Burp Extension. This update introduces a new feature allowing users to import WAS findings directly into Burp Repeater for manual validation.

Previously, informational findings from WAS were not eligible for importing into Repeater. The new version resolves this issue, enabling users to import any finding.

When importing, users can choose from multiple request payloads, if present. For older findings detected before WAS Engine 7.0, some request headers might be missing, requiring manual tweaking of the request format.

This functionality is compatible with both Burp Suite Professional and Burp Suite Community Edition. The extension, developed and released by Qualys, allows users to import findings by entering the finding ID or selecting from a web app's open findings in WAS.

With version 2 of the Qualys WAS Burp Extension, users can now import WAS findings directly into Burp Repeater for manual validation. This update expands the functionality of the extension, making it more versatile for users of both Burp Suite Professional and Burp Suite Community Edition. Users may need to manually adjust session cookies or other authentication tokens in the request.

Read also:

Latest