Site map comparison results

The comparison results highlight differences in the tree and table views of both site maps.

Viewing comparison results

Added, deleted, or modified items are color-coded.

You can view the minimum number of text edits required to convert the response in Map 1 to match the response in Map 2. This is shown in the Diff count column.

When you select a branch or table item in one map, the other map updates to show the same selection. To change this behavior, deselect Sync selection.

You can view the full requests and responses for the selected items in the request / response viewers. Burp highlights relevant differences within the responses.

The display filter applies to both maps. All items are shown by default.

Interpreting comparison results

To interpret the results of a site map comparison, you need to understand the meaning and context of specific application functions. For example:

Any combination of these scenarios can occur in the same application. This makes it more difficult to identify genuine access control problems. The only way to do this is to manually review the comparison results. Burp has several ways to make this process easier:

There are many challenges when you evaluate access controls, which means fully automated tools struggle to find access control vulnerabilities. These automated tools generate lots of noise and are very prone to false positives and negatives. Burp does not attempt to automatically examine the application's functionality, or evaluate how access controls are applied. Instead, the site map automates as much of the process as possible. It presents the information clearly and enables you to apply your knowledge more efficiently, to identify any actual vulnerabilities.