PortSwigger / param-miner

https://portswigger.net/blog/practical-web-cache-poisoning
Other
1.23k stars 166 forks source link

Memory issues #61

Closed Hipapheralkus closed 3 years ago

Hipapheralkus commented 3 years ago

Hi, After I've updated to the newest version, and trying to run Param Miner on host which supports HTTP/2, the extension takes all the memory and doesn't release it at all, unless Burp is restarted. I've disabled Logger, and all other extensions so I'm quite certain the problem is in this one. I've tried both HTTP/1.1 as well as HTTP/2, but it still persists. image My settings are following: image When I start guessing Headers, I can see memory is consumed and once finished, it is still retained (I need to restart Burp). When I try to bruteforce GET parameters, the problem is much worse as I have no idea when it finishes.

albinowax commented 3 years ago

Thanks for the report. We've tracked this down to an issue in Burp Suite 2020.8 and the team is working on getting a release out to fix this ASAP.

albinowax commented 3 years ago

The fix is now out: https://portswigger.net/burp/releases/professional-community-2021-8-1