# Using Burp Suite Bambdas to Find Unusual HTTP Endpoints and Vulnerabilities

DevFeed: [Using Burp Suite Bambdas to Find Unusual HTTP Endpoints and Vulnerabilities](<https://devfeed.tech/articles/finding-that-one-weird-endpoint-with-bambdas-7678.md>)

Original publisher: [Read original article](<https://portswigger.net/research/finding-that-one-weird-endpoint-with-bambdas>)

Author: James Kettle

Published: 2023-12-12T14:11:17Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [http](<https://devfeed.tech/tags/http.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

## AI overview

PortSwigger Research describes using Burp Suite Bambdas to scan a large project file for unusual HTTP responses and potential vulnerabilities. The examples identify authentication-related information disclosure, unexpected source-code leaks, malformed middleware responses, and servers running SMTP on port 443.

## Source excerpt

Security research involves a lot of failure. It's a perpetual balancing act between taking small steps with a predictable but boring outcome, and trying out wild concepts that are so crazy they might