Burp Suite User Forum

Create new post

Burp Suite Enterprise Authentication

Thomas | Last updated: Nov 19, 2018 10:07PM UTC

I'm evaluating Burp Suite Enterprise, and I'm having trouble authenticating the scanner. The target application is served from a.example.com, but authenticates by sending an AJAX request to b.example.com when the login button is clicked. Is there support for authenticating with this kind of setup? And if automatically authenticating isn't possible, is it possible to set a header to be sent on all requests?

PortSwigger Agent | Last updated: Nov 20, 2018 10:42AM UTC

At the moment the crawler does not support JavaScript, so it won't be able to automatically cover this site. This feature has been frequently requested and is on our development plan. It's possible to manually set a cookie, although not an authorization header. You need to use Burp Pro to set up a session handling rule to "Set a specific cookie or parameter value", then export that configuration as JSON and import it into Enterprise. We realize this is not an ideal workflow and we will be improving this in future.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.