Burp Suite User Forum

Create new post

Session Handling - determine session validity not working because of Redirect

Dan | Last updated: Jul 02, 2015 11:44AM UTC

Hello, I have an application which (by design) logs the user out (by redirecting to login page) when inputs don't have a valid value. I need to use the Session Handling to re-login. The log out detection in Burp is inconsistent when "Follow redirections where necessary" (Scanner > Options) is set. Inconsistent because it tests the session validity sometimes before redirecting and sometimes after redirecting. For my setting the ("URL of redirection target") the right spot to test would be before the redirection. Even if you put a response body pattern for invalid session this would cause problems. If "Follow redirections where necessary" is disabled it works OK, but this can cause Burp to not see what really happens after the redirect. Notice: In either cases there will be many False-Negatives. Regards,

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.