Burp Suite User Forum

Create new post

How do I attack OWA 15?

Dan | Last updated: May 09, 2016 10:46PM UTC

The new version of OWA uses javascript to process authentication, and by the looks of it, I can't get burp to do exactly what a browser would do by using intruder. Has anybody ever attacked the newest version of OWA with burp?

PortSwigger Agent | Last updated: May 10, 2016 08:13AM UTC

If you use your browser to perform the login sequence, and capture the traffic via Burp, are you able to create a Burp macro that can sucessfully perform the sequence and obtain a valid session? You might need to configure some custom parameter locations if key values are coming back within JavaScript strings or elsewhere. If you can get a macro working, then you can use that for your Intruder attacks or elsewhere.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.