Dropping out-of-scope requests

In the Options subtab under the Connections tab, we can decide how we would like to treat requests that are out of scope. Out-of-scope requests are any requests that don't match the URL patterns set in the Scope subtab.

A good plan is to drop all out-of-scope requests when you are absolutely sure about what you are attacking. You might want to reconsider based on requirements, especially if you are still figuring out the complete scope or functionality of the application being tested. Take a look at the following screenshot:

Dropping out-of-scope requests

Get Burp Suite Essentials now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.