Burp Suite User Forum

Create new post

Session Handling rules

Fábio | Last updated: Mar 22, 2018 09:56AM UTC

Hi. It would be nice to have an option to update the session headers in the session rules. There exist a simillar option that allows us to update parameters and cookies, so why not the headers? I had an issue where the body of the response passed a value that were injected in an header and I found no easy way to do it, ended up passing it as parameter since luckly the app still parsed it if this was passed in the body instead of beeing in the header.

Burp User | Last updated: Mar 22, 2018 09:57AM UTC

Ups forgot to Thank you! Best Regards, Fábio Gomes

PortSwigger Agent | Last updated: Mar 22, 2018 11:51AM UTC

Hi Fábio, Thanks for getting in touch. I agree, this would be a useful feature. It's been requested a few times and it is on the development plan. Unfortunately, it's likely to be a little time until this is looked at; the development team are working on some more major changes. We'll let you know when we make progress. In the meantime, you can use the Custom Parameter Handler extension to do this. Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.