1N3 / Sn1per

Attack Surface Management Platform
https://sn1persecurity.com
Other
7.9k stars 1.82k forks source link

Safely stopping a burpsuite scan without sacrificing the results from other scans #348

Closed digitizeddude closed 3 years ago

digitizeddude commented 3 years ago

I was running a sniper webscan and burpsuite pro was estimating that the scan would take 10 days to complete. I know the site is massive but i also can't sit on a scan for 10 days. I'm presuming it is getting rate limited or something. Is it ok to just close BurpSuite Pro to allow sn1per to continue the webscan without loosing collected info on other scans for the asset? Sn1per 9 on Kali 2020.4 and BurpSuite? Will it retain the information that was collected on Burpsuite? Is it better to just pause the Burp scan or do i close Burp? I've never had a scan run this long so this is my first time with having to deal with this using sn1per. Sorry if this was answered before. Thanks for the help.

GraylockInc commented 3 years ago

For some reason, 10 days is the default estimate for me too no matter when I'm pointing it as well.

digitizeddude commented 3 years ago

I'm guessing that the 10 day estimate is due to rate limiting being done by the target unless you are whitelisted on their waf or cdn. My scan has been running for at least 2 days with Sn1per and it's only on the burp part of the webscan. The site i'm scanning is fairly large but i just need a way to cut my losses and keep going in case it's too big of a scan using burp or any other tool.

1N3 commented 3 years ago

You should be able to stop any active scans within Burpsuite's scan task viewer and Sn1per will think the scan is complete and should still spit out the results and continue.