Burp Suite User Forum

Create new post

how to find which option or extension edited my requests?

Peter | Last updated: Apr 25, 2018 05:03PM UTC

Hi all, I'm seeing from proxy history that Burp edited POST requests in removing authorization header from original requests. this caused authentication failures for my session. 1. i tried to find out which extension or option did this. but no success. I have unloaded and removed some suspicious extensions. any tips how to trace down the suspect :-) ? 2. In the Alerts window, i saw the two error messages: 1524675283205 Proxy [2] Authentication failure from <host 1> 1524675284712 Proxy [12] Unknown host: <host 2> I tried to get some helpful hints from the error message. don't know what [number] stands for. any burp doc as how to interpret the alerts message. Thanks, Peter

Liam, PortSwigger Agent | Last updated: Apr 26, 2018 09:41AM UTC

1. Have you tried using the Flow extension? This extension provides a Proxy history-like view along with search filter capabilities for all Burp tools. https://portswigger.net/bappstore/ee1c45f4cc084304b2af4b7e92c0a49d 2. If you see entries in the alerts tab relating to authentication failures, then this indicates that platform authentication is required for some of the requests that the Scanner is making. - https://portswigger.net/burp/help/options_connections#platformauth It's possible that some of the URLs requested during host-level active scanning are just being blocked. The "Unknown host" message indicates that Burp wasn't able to resolve the domain name in the URL. This either means that Burp has no web access., or that you need to connect via an upstream proxy server on your LAN. If your browser normally uses a network proxy to connect to the web, you can configure this in Burp at Options / Connections / Upstream proxy servers. Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.